PT-2022-24996 · Sap · Sap Gui For Html

CVE-2022-39799

·

Published

2022-09-13

·

Updated

2025-06-10

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP GUI for HTML (affected versions not specified)
Description The issue allows an attacker with no prior authentication to craft and send malicious scripts to SAP GUI for HTML within Fiori Launchpad, resulting in a reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39799

Affected Products

Sap Gui For Html