First published: Wed May 11 2022(Updated: )
SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server ABAP | =753 | |
SAP NetWeaver Application Server ABAP | =754 | |
SAP NetWeaver Application Server ABAP | =755 | |
SAP NetWeaver Application Server ABAP | =756 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29610 refers to a vulnerability in SAP NetWeaver Application Server ABAP that allows an authenticated attacker to upload malicious files and delete data, potentially leading to a Stored Cross-Site Scripting (XSS) attack.
CVE-2022-29610 has a severity rating of 5.4, which is considered medium.
CVE-2022-29610 affects SAP NetWeaver Application Server ABAP versions 753, 754, 755, and 756.
An authenticated attacker can exploit CVE-2022-29610 by uploading malicious files and deleting (theme) data on the affected SAP NetWeaver Application Server ABAP, potentially leading to a Stored Cross-Site Scripting (XSS) attack.
Yes, SAP has released security notes and patches to address the vulnerability. It is recommended to apply the latest patches provided by SAP.