5.4
CVSSv3

CVE-2022-35297

Published: 11/10/2022 Updated: 12/10/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap enable now 10