Reflected Cross-Site Scripting Vulnerability in SAP GUI for HTML within Fiori Launchpad
CVE-2022-39799

6.1MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 September 2022

Summary

A vulnerability exists in SAP GUI for HTML within the Fiori Launchpad, allowing potentially malicious actors to execute a reflected cross-site scripting attack. An attacker could send crafted malicious scripts without prior authentication, targeting the SAP GUI for HTML. This exploitation could result in the theft of session information, granting the attacker the ability to impersonate users and gain unauthorized access to sensitive data and functionality.

Affected Version(s)

SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) KERNEL 7.77

SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) 7.81

SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad) 7.85

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.