PT-2022-25774 · Sap · Sap Netweaver As Java

Published

2022-12-12

·

Updated

2023-01-10

·

CVE-2022-41262

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS Java (HTTP Provider Service) version 7.50
Description The issue is caused by insufficient input validation, allowing an unauthenticated attacker to inject a script into a web request header. Successful exploitation enables an attacker to view or modify information, resulting in a limited impact on the confidentiality and integrity of the application.
Recommendations For version 7.50, update to a version that includes input validation for the HTTP Provider Service to prevent script injection attacks. As a temporary workaround, consider restricting access to the HTTP Provider Service to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-41262

Affected Products

Sap Netweaver As Java