Medium severity6.1NVD Advisory· Published Jan 14, 2022· Updated Jun 17, 2026
CVE-2022-22529
CVE-2022-22529
Description
SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD are using SAP UI5 standard controls, the UI5 framework provides automated output encoding for its standard controls. This output encoding prevents stored malicious user input from being executed when it is reflected in the UI.
Affected products
3- SAP SE/SAP Enterprise Threat Detectionv5Range: 2.0
2.0+ 1 more
- (no CPE)range: 2.0
- cpe:2.3:a:sap:enterprise_threat_detection:2.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.