CVE-2022-29610: XSS
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29610?
CVE-2022-29610 refers to a vulnerability in SAP NetWeaver Application Server ABAP that allows an authenticated attacker to upload malicious files and delete data, potentially leading to a Stored Cross-Site Scripting (XSS) attack.
What is the severity of CVE-2022-29610?
CVE-2022-29610 has a severity rating of 5.4, which is considered medium.
How does CVE-2022-29610 affect SAP NetWeaver Application Server ABAP?
CVE-2022-29610 affects SAP NetWeaver Application Server ABAP versions 753, 754, 755, and 756.
How can an attacker exploit CVE-2022-29610?
An authenticated attacker can exploit CVE-2022-29610 by uploading malicious files and deleting (theme) data on the affected SAP NetWeaver Application Server ABAP, potentially leading to a Stored Cross-Site Scripting (XSS) attack.
Is there a fix available for CVE-2022-29610?
Yes, SAP has released security notes and patches to address the vulnerability. It is recommended to apply the latest patches provided by SAP.