First published: Wed Feb 09 2022(Updated: )
Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Business Objects Web Intelligence (BI Launchpad) - version 420.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP BusinessObjects Web Intelligence | =420 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22546 is medium, with a severity value of 5.4.
The affected software of CVE-2022-22546 is SAP BusinessObjects Web Intelligence version 420.
An attacker can exploit CVE-2022-22546 by executing an XSS vulnerability through improper HTML encoding in the input control summary.
To fix CVE-2022-22546, it is recommended to apply the necessary security patches provided by SAP.
You can find more information about CVE-2022-22546 in the SAP support notes (https://launchpad.support.sap.com/#/notes/3126748) and the SAP documentation (https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).