VDB
CVE-2022-35298
CVE-2022-35298
PUBLISHED
SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability. KMC servlet is vulnerable to XSS attack. The execution of script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser session.
EPSS 0.54% · 67.9th percentile
Risk Scores
EPSS Score
0.54%
67.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP SE | SAP NetWeaver Enterprise Portal (KMC) | 7.50 |
| sap | netweaver_enterprise_portal | 7.50 |
Exploit Intelligence
Timeline
- Sep 13, 2022 CVE Published
- Sep 14, 2022 EPSS Score
- Sep 16, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 13, 2022 EPSS Score
- Jan 27, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- Apr 27, 2023 EPSS Score
- Jul 26, 2023 EPSS Score
- Sep 9, 2023 EPSS Score
- Oct 24, 2023 EPSS Score
References
- https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=1&todaysdate=2022-09-14 advisory
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html url
- https://launchpad.support.sap.com/#/notes/3219164 url
- https://github.com/cla-assistant/cla-assistant/security/advisories/GHSA-jjjv-grgr-v8h3 url
- https://nvd.nist.gov/vuln/detail/CVE-2022-35298 advisory