Medium severity6.1NVD Advisory· Published Apr 12, 2022· Updated Jun 17, 2026
CVE-2022-26105
CVE-2022-26105
Description
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the user inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Affected products
9- Range: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
cpe:2.3:a:sap:netweaver_enterprise_portal:7.10:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.10:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.11:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.20:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.50:*:*:*:*:*:*:*
- SAP SE/SAP NetWeaver Enterprise Portalv5Range: 7.10
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.