CVE-2022-29618: XSS
Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29618?
CVE-2022-29618 is considered a high severity vulnerability due to its potential for code injection and execution in user browsers.
How do I fix CVE-2022-29618?
To remediate CVE-2022-29618, update SAP NetWeaver Development Infrastructure to the latest patched version provided by SAP.
What systems are affected by CVE-2022-29618?
CVE-2022-29618 affects SAP NetWeaver Development Infrastructure versions 7.30, 7.31, 7.40, and 7.50.
What type of attack is enabled by CVE-2022-29618?
CVE-2022-29618 enables unauthenticated attackers to perform cross-site scripting (XSS) attacks through script injection.
Who can exploit CVE-2022-29618?
CVE-2022-29618 can be exploited by unauthenticated attackers, making it particularly dangerous for exposed systems.