SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3163583 | Permissions Required Vendor Advisory |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Apr 2022, 19:09
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sap:netweaver_enterprise_portal:7.10:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_enterprise_portal:7.40:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_enterprise_portal:7.50:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_enterprise_portal:7.20:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_enterprise_portal:7.11:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_enterprise_portal:7.30:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_enterprise_portal:7.31:*:*:*:*:*:*:* |
|
References | (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory | |
References | (MISC) https://launchpad.support.sap.com/#/notes/3163583 - Permissions Required, Vendor Advisory | |
First Time |
Sap
Sap netweaver Enterprise Portal |
|
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.1 |
12 Apr 2022, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-04-12 17:15
Updated : 2023-12-10 14:22
NVD link : CVE-2022-26105
Mitre link : CVE-2022-26105
CVE.ORG link : CVE-2022-26105
JSON object : View
Products Affected
sap
- netweaver_enterprise_portal
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')