VYPR
Medium severity6.1NVD Advisory· Published Mar 10, 2022· Updated Jun 17, 2026

CVE-2022-24399

CVE-2022-24399

Description

The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipart/form-data, resulting in Cross-Site Scripting (XSS) vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • SAP/Focused Run2 versions
    cpe:2.3:a:sap:focused_run:200:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:focused_run:200:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:focused_run:300:*:*:*:*:*:*:*
  • Range: 200, 300
  • SAP SE/SAP Focused Run (Real User Monitoring)v5
    Range: < 200

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.