CVE-2022-35294
13.09.2022, 16:15
An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Server ABAP, which is then downloaded and viewed by other users resulting in a stored Cross-Site-Scripting attack. This could lead to information disclosure including stealing authentication information and impersonating the affected user.
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver_application_server_abap | 7.22ext:ext |
| sap | netweaver_application_server_abap | 7.49 |
| sap | netweaver_application_server_abap | 7.53 |
| sap | netweaver_application_server_abap | 7.54 |
| sap | netweaver_application_server_abap | 7.77 |
| sap | netweaver_application_server_abap | 7.81 |
| sap | netweaver_application_server_abap | 7.85 |
| sap | netweaver_application_server_abap | 7.89 |
𝑥
= Vulnerable software versions