CVE-2022-35298 PUBLISHED

SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser session.

EPSS 0.54% · 67.4th percentile

Risk Scores

EPSS Score
0.54%
67.4th percentile

Affected Products

VendorProductVersions
SAP SESAP NetWeaver Enterprise Portal (KMC)7.50
sapnetweaver_enterprise_portal7.50

Timeline

References

Open in Interactive Console →