CVE-2022-22546: XSS
Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad) - version 420.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22546?
The severity of CVE-2022-22546 is medium, with a severity value of 5.4.
What is the affected software of CVE-2022-22546?
The affected software of CVE-2022-22546 is SAP BusinessObjects Web Intelligence version 420.
How can an attacker exploit CVE-2022-22546?
An attacker can exploit CVE-2022-22546 by executing an XSS vulnerability through improper HTML encoding in the input control summary.
How to fix CVE-2022-22546?
To fix CVE-2022-22546, it is recommended to apply the necessary security patches provided by SAP.
Where can I find more information about CVE-2022-22546?
You can find more information about CVE-2022-22546 in the SAP support notes (https://launchpad.support.sap.com/#/notes/3126748) and the SAP documentation (https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).