CVE-2022-22534

MEDIUM

SAP NetWeaver - Unauthenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may expose sensitive data like user ID and password. These endpoints are normally exposed over the network and successful exploitation can partially impact confidentiality of the application.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/3124994

Scores

CVSS v3 6.1
EPSS 0.0120
EPSS Percentile 79.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (12)
sap/netweaver 700
sap/netweaver 701
sap/netweaver 702
sap/netweaver 731
sap/netweaver 740
sap/netweaver 750
sap/netweaver 751
sap/netweaver 752
sap/netweaver 753
sap/netweaver 754
... and 2 more
Published Feb 09, 2022
Tracked Since Feb 18, 2026