Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-27656


The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.


Published

2022-05-11T15:15:09.677

Last Modified

2024-11-21T06:56:06.843

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_as_abap_kernel 7.22 Yes
Application sap netweaver_as_abap_kernel 7.49 Yes
Application sap netweaver_as_abap_kernel 7.53 Yes
Application sap netweaver_as_abap_kernel 7.77 Yes
Application sap netweaver_as_abap_kernel 7.81 Yes
Application sap netweaver_as_abap_kernel 7.85 Yes
Application sap netweaver_as_abap_kernel 7.86 Yes
Application sap netweaver_as_abap_kernel 7.87 Yes
Application sap netweaver_as_abap_kernel 8.04 Yes
Application sap netweaver_as_abap_krnl64uc 7.22 Yes
Application sap netweaver_as_abap_krnl64uc 7.22ext Yes
Application sap netweaver_as_abap_krnl64uc 7.49 Yes
Application sap netweaver_as_abap_krnl64uc 7.53 Yes
Application sap netweaver_as_abap_krnl64uc 8.04 Yes
Application sap webdispatcher 7.22ext Yes
Application sap webdispatcher 7.49 Yes
Application sap webdispatcher 7.53 Yes
Application sap webdispatcher 7.77 Yes
Application sap webdispatcher 7.81 Yes
Application sap webdispatcher 7.83 Yes
Application sap webdispatcher 7.85 Yes

References