Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35294


An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.


Published

2022-09-13T16:15:08.877

Last Modified

2024-11-21T07:11:03.857

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_application_server_abap 7.22ext Yes
Application sap netweaver_application_server_abap 7.49 Yes
Application sap netweaver_application_server_abap 7.53 Yes
Application sap netweaver_application_server_abap 7.54 Yes
Application sap netweaver_application_server_abap 7.77 Yes
Application sap netweaver_application_server_abap 7.81 Yes
Application sap netweaver_application_server_abap 7.85 Yes
Application sap netweaver_application_server_abap 7.89 Yes
Application sap netweaver_application_server_abap kernel_7.22 Yes
Application sap netweaver_application_server_abap krnl64nuc_7.22 Yes
Application sap netweaver_application_server_abap krnl64uc_7.22 Yes

References