VDB

CVE-2022-35298

CVE-2022-35298 PUBLISHED

SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser session.

EPSS 0.54% · 67.9th percentile

Risk Scores

EPSS Score
0.54%
67.9th percentile

Affected Products

VendorProductVersions
SAP SESAP NetWeaver Enterprise Portal (KMC)7.50
sapnetweaver_enterprise_portal7.50

Timeline

  • Sep 13, 2022 CVE Published
  • Sep 14, 2022 EPSS Score
  • Sep 16, 2022 EPSS Score
  • Oct 29, 2022 EPSS Score
  • Dec 13, 2022 EPSS Score
  • Jan 27, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 13, 2023 EPSS Score
  • Apr 27, 2023 EPSS Score
  • Jul 26, 2023 EPSS Score
  • Sep 9, 2023 EPSS Score
  • Oct 24, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›