CVE-2022-26105: XSS
Published Apr 12, 2022
·Updated
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Affected Software
7 affected components
SAP NetWeaver Enterprise Portal=7.10
SAP NetWeaver Enterprise Portal=7.11
SAP NetWeaver Enterprise Portal=7.20
SAP NetWeaver Enterprise Portal=7.30
SAP NetWeaver Enterprise Portal=7.31
SAP NetWeaver Enterprise Portal=7.40
SAP NetWeaver Enterprise Portal=7.50
Event History
Apr 12, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-26105?
The severity of CVE-2022-26105 is rated as medium with a CVSS score of 6.1 out of 10.
2
How can I fix the vulnerability CVE-2022-26105?
To fix CVE-2022-26105, it is recommended to apply the patches provided by SAP as soon as possible.
3
What can happen if CVE-2022-26105 is successfully exploited?
If CVE-2022-26105 is successfully exploited, an attacker can view or modify sensitive information on the SAP NetWeaver Enterprise Portal without proper authentication.