CVE-2022-35225: XSS
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35225?
CVE-2022-35225 has been classified as a moderate severity vulnerability due to its potential for reflected Cross-Site Scripting impacts.
How do I fix CVE-2022-35225?
To fix CVE-2022-35225, it is recommended to update SAP NetWeaver Enterprise Portal to the latest version that addresses this vulnerability.
What versions of SAP NetWeaver Enterprise Portal are affected by CVE-2022-35225?
CVE-2022-35225 affects SAP NetWeaver Enterprise Portal versions 7.10 through 7.50.
What type of vulnerability is CVE-2022-35225?
CVE-2022-35225 is a reflected Cross-Site Scripting (XSS) vulnerability resulting from insufficient encoding of user-controlled inputs.
What is the impact of CVE-2022-35225?
The impact of CVE-2022-35225 includes the potential for attackers to exploit the XSS vulnerability, compromising user sessions or manipulating user interaction.