Security Advisory
CVE-2022-35170
6.1
MEDIUM
Vulnerability Description
SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.
Published Date
July 12, 2022
Official Source
NIST NVD Advisory