CVE-2022-35172: XSS
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35172?
CVE-2022-35172 has a moderate severity rating due to the potential for reflected Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2022-35172?
To fix CVE-2022-35172, update your SAP NetWeaver Enterprise Portal to the latest version that addresses this vulnerability.
What systems are affected by CVE-2022-35172?
CVE-2022-35172 affects SAP NetWeaver Enterprise Portal versions 7.10 through 7.50.
What is reflected Cross-Site Scripting as it relates to CVE-2022-35172?
Reflected Cross-Site Scripting in CVE-2022-35172 allows attackers to inject malicious scripts via user-controlled inputs.
Has CVE-2022-35172 been exploited in the wild?
As of the latest information, there are no confirmed reports of CVE-2022-35172 being actively exploited in the wild.