CVE-2022-39799: XSS
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2022-39799.
What is the severity of CVE-2022-39799?
The severity of CVE-2022-39799 is medium.
What is the affected software?
The affected software is SAP NetWeaver Application Server ABAP versions 7.54, 7.81, 7.85, and 7.89, as well as SAP NetWeaver Application Server ABAP kernel version 7.77.
How does this vulnerability occur?
This vulnerability occurs when an attacker crafts and sends malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in a reflected cross-site scripting attack.
What are the potential consequences of this vulnerability?
The potential consequences of this vulnerability include stealing session information and impersonating the affected user.