Unrated severityNVD Advisory· Published May 11, 2022· Updated Aug 3, 2024
CVE-2022-27656
CVE-2022-27656
Description
The Web administration UI of SAP Web Dispatcher and the Internet Communication Manager (ICM) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected products
4- SAP SE/SAP NetWeaver AS for ABAP and Java (ICM Administration UI)v5Range: KRNL64NUC 7.22
- SAP SE/SAP Web Dispatcher (Web Administration UI)v5Range: 7.49
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.commitrex_refsource_MISC
- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.