CVE-2022-24395: XSS
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24395?
CVE-2022-24395 has a severity rating that indicates a critical risk for reflected Cross-Site Scripting (XSS) in multiple versions of SAP NetWeaver Enterprise Portal.
How do I fix CVE-2022-24395?
To fix CVE-2022-24395, apply the latest patches provided by SAP for the affected versions of SAP NetWeaver Enterprise Portal.
Which versions of SAP NetWeaver Enterprise Portal are affected by CVE-2022-24395?
CVE-2022-24395 affects SAP NetWeaver Enterprise Portal versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50.
What type of vulnerability is CVE-2022-24395?
CVE-2022-24395 is a reflected Cross-Site Scripting (XSS) vulnerability due to insufficient encoding of user-controlled inputs.
How can attackers exploit CVE-2022-24395?
Attackers can exploit CVE-2022-24395 by tricking users into clicking on malicious links that execute scripts in the context of the user’s session.