Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-26105


SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.


Published

2022-04-12T17:15:09.567

Last Modified

2024-11-21T06:53:26.343

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_enterprise_portal 7.10 Yes
Application sap netweaver_enterprise_portal 7.11 Yes
Application sap netweaver_enterprise_portal 7.20 Yes
Application sap netweaver_enterprise_portal 7.30 Yes
Application sap netweaver_enterprise_portal 7.31 Yes
Application sap netweaver_enterprise_portal 7.40 Yes
Application sap netweaver_enterprise_portal 7.50 Yes

References