4.3
CVSSv2

CVE-2022-35227

Published: 12/07/2022 Updated: 20/07/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controlled input, allows a remote malicious user to conduct a Cross-Site (XSS) scripting attack. A successful exploit could allow the malicious user to execute arbitrary script code which could lead to stealing or modifying of authentication information of the user, such as data relating to his or her current session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver enterprise portal 7.31

sap netweaver enterprise portal 7.30

sap netweaver enterprise portal 7.40

sap netweaver enterprise portal 7.50