Medium severity6.1NVD Advisory· Published Jul 12, 2022· Updated Jun 17, 2026
CVE-2022-32247
CVE-2022-32247
Description
SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unauthenticated attacker due to improper sanitization of the User inputs while interacting on the Network. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.
Affected products
9- Range: 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50
cpe:2.3:a:sap:netweaver_enterprise_portal:7.10:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.10:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.11:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.20:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.30:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.40:*:*:*:*:*:*:*
- cpe:2.3:a:sap:netweaver_enterprise_portal:7.50:*:*:*:*:*:*:*
- SAP SE/SAP NetWeaver Enterprise Portalv5Range: 7.10
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.