First published: Tue Mar 08 2022(Updated: )
The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipart/form-data, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Focused Run | =200 | |
SAP Focused Run | =300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24399 is a Cross-Site Scripting (XSS) vulnerability found in the SAP Focused Run (Real User Monitoring) versions 200 and 300 REST service.
The severity of CVE-2022-24399 is medium, with a CVSS score of 6.1.
CVE-2022-24399 affects SAP Focused Run (Real User Monitoring) versions 200 and 300.
CVE-2022-24399 has a CWE of 79, which is Cross-Site Scripting (XSS).
To fix the CVE-2022-24399 vulnerability, apply the necessary security patches provided by SAP for the affected versions of SAP Focused Run (Real User Monitoring).