PT-2022-22693 · Sap · Sap Netweaver Application Server Abap

Published

2022-09-13

·

Updated

2022-10-05

·

CVE-2022-35294

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP (affected versions not specified)
Description The issue allows an attacker with basic business user privileges to craft and upload a malicious file, which is then downloaded and viewed by other users, resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure, including stealing authentication information and impersonating the affected user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-35294

Affected Products

Sap Netweaver Application Server Abap