CVE-2022-35224: XSS
SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-permanently deface or modify portal content. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim?s web browser session.
Other sources
SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. This attack can be used to non-permanently deface or modify portal content. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim�s web browser session.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35224?
CVE-2022-35224 is classified as a medium severity vulnerability due to its potential impact on web application integrity.
How do I fix CVE-2022-35224?
To fix CVE-2022-35224, update the SAP Enterprise Portal to the latest version that includes patches for this vulnerability.
What version of SAP Enterprise Portal is affected by CVE-2022-35224?
CVE-2022-35224 affects SAP Enterprise Portal versions 7.10 through 7.50.
What type of vulnerability is CVE-2022-35224?
CVE-2022-35224 is a Cross-Site Scripting (XSS) vulnerability caused by improper encoding of user-controlled inputs.
What are the potential risks associated with CVE-2022-35224?
The risks associated with CVE-2022-35224 include the potential for attackers to execute scripts that deface or modify portal content.