PT-2022-16674 · Sap · Sap Focused Run

Yvan Genuer

·

Published

2022-03-08

·

Updated

2022-12-22

·

CVE-2022-24399

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Focused Run (Real User Monitoring) versions 200, 300
Description The issue is related to a Cross-Site Scripting (XSS) vulnerability. It occurs because the REST service does not sufficiently sanitize the input name of the file using multipart/form-data. This lack of proper sanitization can lead to security issues.
Recommendations For versions 200 and 300, consider restricting access to the REST service until a proper fix is applied, focusing on sanitizing the input name of the file using multipart/form-data to prevent Cross-Site Scripting (XSS) attacks. As a temporary workaround, disabling the REST service or limiting its functionality can help minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-24399

Affected Products

Sap Focused Run