CVE-2022-27656 PUBLISHED CVSS 6.099999904632568 MEDIUM

The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

EPSS 0.39% · 60.1th percentile

Risk Scores

CVSS v3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.39%
60.1th percentile

Affected Products

VendorProductVersions
sapnetweaver_as_abap_kernel7.49, 7.53, 7.77
sapnetweaver_as_abap_krnl64uc7.22ext, 7.49, 7.53
SAP SESAP Web Dispatcher (Web Administration UI)7.53, 7.77, 7.81
SAP SESAP NetWeaver AS for ABAP and Java (ICM Administration UI)KRNL64NUC 7.22, 7.22EXT, 7.49
sapwebdispatcher7.22ext, 7.49, 7.53

Timeline

References

Open in Interactive Console →