CVE-2022-24399: XSS
Published Mar 8, 2022
·Updated
The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipart/form-data, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
2 affected components
SAP Focused Run=200
SAP Focused Run=300
Event History
Mar 8, 2022
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-24399?
CVE-2022-24399 is a Cross-Site Scripting (XSS) vulnerability found in the SAP Focused Run (Real User Monitoring) versions 200 and 300 REST service.
2
What is the severity of CVE-2022-24399?
The severity of CVE-2022-24399 is medium, with a CVSS score of 6.1.
3
How does CVE-2022-24399 affect SAP Focused Run?
CVE-2022-24399 affects SAP Focused Run (Real User Monitoring) versions 200 and 300.
4
What is the Common Weakness Enumeration (CWE) of CVE-2022-24399?
CVE-2022-24399 has a CWE of 79, which is Cross-Site Scripting (XSS).
5
How can I fix the CVE-2022-24399 vulnerability?
To fix the CVE-2022-24399 vulnerability, apply the necessary security patches provided by SAP for the affected versions of SAP Focused Run (Real User Monitoring).