First published: Tue Sep 13 2022(Updated: )
SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser session.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver (Enterprise Portal) | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35298 is classified as a medium severity Cross-Site Scripting vulnerability.
To mitigate CVE-2022-35298, ensure you are using the latest patched version of SAP NetWeaver Enterprise Portal.
CVE-2022-35298 specifically affects SAP NetWeaver Enterprise Portal version 7.50.
CVE-2022-35298 is associated with Cross-Site Scripting (XSS) attacks.
Exploitation of CVE-2022-35298 may allow an attacker to execute malicious scripts in the context of a victim's session.