Cross-Site Scripting Vulnerability in SAP NW EP by SAP
CVE-2022-35227
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 July 2022
What is CVE-2022-35227?
A vulnerability identified in SAP NW EP (WPC) across several versions (7.30, 7.31, 7.40, 7.50) arises from insufficient validation of user-controlled input. This flaw can enable remote attackers to perform Cross-Site Scripting (XSS) attacks, potentially allowing them to execute arbitrary script code. Such exploitation could result in the theft or unauthorized alteration of sensitive authentication information from users, impacting their current sessions and compromising the integrity of their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver Enterprise Portal (WPC) 7.30
SAP NetWeaver Enterprise Portal (WPC) 7.31
SAP NetWeaver Enterprise Portal (WPC) 7.40
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved