CVE-2022-27656: XSS
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-27656.
What is the severity level of CVE-2022-27656?
The severity level of CVE-2022-27656 is medium with a CVSS score of 6.1.
What software versions are affected by CVE-2022-27656?
SAP Netweaver AS ABAP Kernel versions 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 8.04, and Sap Webdispatcher versions 7.22ext, 7.49, 7.53, 7.77, 7.81, 7.83, and 7.85 are affected by CVE-2022-27656.
What is the vulnerability description of CVE-2022-27656?
CVE-2022-27656 is a Cross-Site Scripting (XSS) vulnerability in the Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) due to insufficient encoding of user-controlled inputs.
Are there any references available for CVE-2022-27656?
Yes, the references for CVE-2022-27656 are: [SAP Note 3145046](https://launchpad.support.sap.com/#/notes/3145046) and [SAP Security Advisory](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).