Medium severity6.1NVD Advisory· Published Mar 10, 2022· Updated Jun 17, 2026
CVE-2022-24399
CVE-2022-24399
Description
The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input name of the file using multipart/form-data, resulting in Cross-Site Scripting (XSS) vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:sap:focused_run:200:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:focused_run:200:*:*:*:*:*:*:*
- cpe:2.3:a:sap:focused_run:300:*:*:*:*:*:*:*
- Range: 200, 300
- SAP SE/SAP Focused Run (Real User Monitoring)v5Range: < 200
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/167559/SAP-FRUN-2.00-3.00-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2022/Jun/37nvdExploitMailing ListThird Party Advisory
- dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htmnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
News mentions
0No linked articles in our index yet.