An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.
2022-09-13T16:15:08.877
2024-11-21T07:11:03.857
Modified
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | netweaver_application_server_abap | 7.22ext | Yes |
Application | sap | netweaver_application_server_abap | 7.49 | Yes |
Application | sap | netweaver_application_server_abap | 7.53 | Yes |
Application | sap | netweaver_application_server_abap | 7.54 | Yes |
Application | sap | netweaver_application_server_abap | 7.77 | Yes |
Application | sap | netweaver_application_server_abap | 7.81 | Yes |
Application | sap | netweaver_application_server_abap | 7.85 | Yes |
Application | sap | netweaver_application_server_abap | 7.89 | Yes |
Application | sap | netweaver_application_server_abap | kernel_7.22 | Yes |
Application | sap | netweaver_application_server_abap | krnl64nuc_7.22 | Yes |
Application | sap | netweaver_application_server_abap | krnl64uc_7.22 | Yes |