PT-2022-25773 · Sap · Sap Financial Consolidation
Published
2022-11-08
·
Updated
2022-12-09
·
CVE-2022-41260
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Financial Consolidation version 1010
Description
The issue arises from insufficient encoding of user-controlled input, allowing an unauthenticated attacker to inject a web script via a GET request. Successful exploitation can lead to an attacker viewing or modifying information, resulting in a limited impact on the confidentiality and integrity of the application.
Recommendations
For SAP Financial Consolidation version 1010, update to a version that sufficiently encodes user-controlled input to prevent web script injection via GET requests. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Financial Consolidation