Reflected Cross-Site Scripting Vulnerability in SAP GUI for HTML within Fiori Launchpad
CVE-2022-39799
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 September 2022
What is CVE-2022-39799?
A vulnerability exists in SAP GUI for HTML within the Fiori Launchpad, allowing potentially malicious actors to execute a reflected cross-site scripting attack. An attacker could send crafted malicious scripts without prior authentication, targeting the SAP GUI for HTML. This exploitation could result in the theft of session information, granting the attacker the ability to impersonate users and gain unauthorized access to sensitive data and functionality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) KERNEL 7.77
SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) 7.81
SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) 7.85
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved