Show filters
132 Total Results
Displaying 31-40 of 132
Sort by:
Attacker Value
Unknown

CVE-2022-35172

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2022-35170

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-controlled inputs over the network, resulting in reflected Cross-Site Scripting (XSS) vulnerability, therefore changing the scope of the attack. This leads to limited impact on confidentiality and integrity of data.
Attacker Value
Unknown

CVE-2022-32247

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2022-29618

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2022-29615

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The application's confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.
Attacker Value
Unknown

CVE-2022-28217

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrusted source, which allows an adversary to exploit unprotected XML parking at endpoints, and a possibility to conduct SSRF attacks that could compromise system�s Availability by causing system to crash.
Attacker Value
Unknown

CVE-2022-27669

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - version 7.50, to which access should be restricted. This may result in an escalation of privileges.
Attacker Value
Unknown

CVE-2022-26105

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Attacker Value
Unknown

CVE-2022-26103

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
Attacker Value
Unknown

CVE-2022-24397

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser.