First published: Wed May 11 2022(Updated: )
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Netweaver As Abap Kernel | =7.22 | |
Sap Netweaver As Abap Kernel | =7.49 | |
Sap Netweaver As Abap Kernel | =7.53 | |
Sap Netweaver As Abap Kernel | =7.77 | |
Sap Netweaver As Abap Kernel | =7.81 | |
Sap Netweaver As Abap Kernel | =7.85 | |
Sap Netweaver As Abap Kernel | =7.86 | |
Sap Netweaver As Abap Kernel | =7.87 | |
Sap Netweaver As Abap Kernel | =8.04 | |
Sap Netweaver As Abap Krnl64uc | =7.22 | |
Sap Netweaver As Abap Krnl64uc | =7.22ext | |
Sap Netweaver As Abap Krnl64uc | =7.49 | |
Sap Netweaver As Abap Krnl64uc | =7.53 | |
Sap Netweaver As Abap Krnl64uc | =8.04 | |
Sap Webdispatcher | =7.22ext | |
Sap Webdispatcher | =7.49 | |
Sap Webdispatcher | =7.53 | |
Sap Webdispatcher | =7.77 | |
Sap Webdispatcher | =7.81 | |
Sap Webdispatcher | =7.83 | |
Sap Webdispatcher | =7.85 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2022-27656.
The severity level of CVE-2022-27656 is medium with a CVSS score of 6.1.
SAP Netweaver AS ABAP Kernel versions 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 8.04, and Sap Webdispatcher versions 7.22ext, 7.49, 7.53, 7.77, 7.81, 7.83, and 7.85 are affected by CVE-2022-27656.
CVE-2022-27656 is a Cross-Site Scripting (XSS) vulnerability in the Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) due to insufficient encoding of user-controlled inputs.
Yes, the references for CVE-2022-27656 are: [SAP Note 3145046](https://launchpad.support.sap.com/#/notes/3145046) and [SAP Security Advisory](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).