VDB

CVE-2022-27656

CVE-2022-27656 PUBLISHED CVSS 6.099999904632568 MEDIUM

The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

EPSS 0.32% · 55.7th percentile

Risk Scores

CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.32%
55.7th percentile

Affected Products

VendorProductVersions
sapnetweaver_as_abap_kernel7.87, 8.04, 7.85
sapnetweaver_as_abap_krnl64uc7.49, 7.53, 7.22
SAP SESAP Web Dispatcher (Web Administration UI)7.53, 7.77, 7.81
SAP SESAP NetWeaver AS for ABAP and Java (ICM Administration UI)KRNL64NUC 7.22, 7.22EXT, 7.22
sapwebdispatcher7.85, 7.83, 7.81

Exploit Intelligence

…and 16 more exploits

Timeline

  • Apr 7, 2022 PoC Published
  • May 11, 2022 CVE Published
  • May 12, 2022 EPSS Score
  • Jun 30, 2022 EPSS Score
  • Aug 19, 2022 EPSS Score
  • Oct 8, 2022 EPSS Score
  • Nov 26, 2022 EPSS Score
  • Jan 14, 2023 EPSS Score
  • Mar 4, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 23, 2023 EPSS Score
  • Jun 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›