CVE-2022-26101: XSS
Published Mar 8, 2022
·Updated
Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
3 affected components
SAP Fiori Launchpad=754
SAP Fiori Launchpad=755
SAP Fiori Launchpad=756
Event History
Mar 8, 2022
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-26101?
The severity of CVE-2022-26101 is classified as medium due to its potential to allow Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2022-26101?
To fix CVE-2022-26101, update your SAP Fiori Launchpad to a version that implements proper input encoding.
3
Which versions are affected by CVE-2022-26101?
CVE-2022-26101 affects SAP Fiori Launchpad versions 754, 755, and 756.
4
What type of vulnerability is CVE-2022-26101?
CVE-2022-26101 is a Cross-Site Scripting (XSS) vulnerability due to insufficient input encoding.
5
What are the consequences of CVE-2022-26101?
The consequences of CVE-2022-26101 may include unauthorized access to user sessions and data manipulation through XSS attacks.