CVE-2022-39799
13.09.2022, 16:15
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
| Vendor | Product | Version |
|---|---|---|
| sap | netweaver_application_server_abap | 7.54 |
| sap | netweaver_application_server_abap | 7.81 |
| sap | netweaver_application_server_abap | 7.85 |
| sap | netweaver_application_server_abap | 7.89 |
𝑥
= Vulnerable software versions