VDB

CVE-2022-29610

CVE-2022-29610 PUBLISHED CVSS 3.5 LOW

SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.

EPSS 0.30% · 53.9th percentile

Risk Scores

CVSS 2.0
3.5
EPSS Score
0.30%
53.9th percentile

Affected Products

VendorProductVersions
sapnetweaver_application_server_abap755, 753, 754
SAP SESAP NetWeaver Application Server ABAP753, 754, 755

Exploit Intelligence

…and 16 more exploits

Timeline

  • Apr 7, 2022 PoC Published
  • May 11, 2022 CVE Published
  • May 12, 2022 EPSS Score
  • Jun 30, 2022 EPSS Score
  • Aug 19, 2022 EPSS Score
  • Oct 8, 2022 EPSS Score
  • Nov 26, 2022 EPSS Score
  • Jan 14, 2023 EPSS Score
  • Mar 4, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 23, 2023 EPSS Score
  • Jun 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›