CVE-2022-35170: XSS
SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35170?
CVE-2022-35170 is classified as a moderate severity reflected Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2022-35170?
To remediate CVE-2022-35170, ensure user inputs are properly encoded and validated before processing.
Which SAP NetWeaver Enterprise Portal versions are affected by CVE-2022-35170?
SAP NetWeaver Enterprise Portal versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 are all affected by CVE-2022-35170.
What impact does CVE-2022-35170 have on applications?
CVE-2022-35170 can potentially allow attackers to execute malicious scripts in the context of the user's browser.
Is there any patch available for CVE-2022-35170?
SAP has released a security note that includes guidance on applying necessary patches to mitigate CVE-2022-35170.