CVE-2022-39799

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 September 2022

Summary

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

Affected Version(s)

SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) KERNEL 7.77

SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) 7.81

SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) 7.85

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.