CVE-2022-24397: XSS
SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-24397.
What is the severity of CVE-2022-24397?
The severity of CVE-2022-24397 is medium.
Which versions of SAP NetWeaver Enterprise Portal are affected by this vulnerability?
Versions 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver Enterprise Portal are affected by this vulnerability.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-79.
How can I fix the reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal?
To fix the reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, apply the necessary patches or updates provided by SAP.