6.1

CVE-2022-27656

The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Data is provided by the National Vulnerability Database (NVD)
SAPNetweaver As Abap Kernel Version7.22
SAPNetweaver As Abap Kernel Version7.49
SAPNetweaver As Abap Kernel Version7.53
SAPNetweaver As Abap Kernel Version7.77
SAPNetweaver As Abap Kernel Version7.81
SAPNetweaver As Abap Kernel Version7.85
SAPNetweaver As Abap Kernel Version7.86
SAPNetweaver As Abap Kernel Version7.87
SAPNetweaver As Abap Kernel Version8.04
SAPNetweaver As Abap Krnl64uc Version7.22ext
SAPWebdispatcher Version7.22ext
SAPWebdispatcher Version7.49
SAPWebdispatcher Version7.53
SAPWebdispatcher Version7.77
SAPWebdispatcher Version7.81
SAPWebdispatcher Version7.83
SAPWebdispatcher Version7.85
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.558
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.