PT-2022-25774 · Sap · Sap Netweaver As Java
Published
2022-12-12
·
Updated
2023-01-10
·
CVE-2022-41262
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver AS Java (HTTP Provider Service) version 7.50
Description
The issue is caused by insufficient input validation, allowing an unauthenticated attacker to inject a script into a web request header. Successful exploitation enables an attacker to view or modify information, resulting in a limited impact on the confidentiality and integrity of the application.
Recommendations
For version 7.50, update to a version that includes input validation for the HTTP Provider Service to prevent script injection attacks. As a temporary workaround, consider restricting access to the HTTP Provider Service to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As Java