High severity8.0NVD Advisory· Published Dec 13, 2022· Updated Jun 17, 2026
CVE-2022-41266
CVE-2022-41266
Description
Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a DOM Cross-Site Scripting (XSS) attack. As a result, an attacker may be able to steal user tokens and achieve a full account takeover including access to administrative tools in SAP Commerce.
Affected products
7cpe:2.3:a:sap:commerce_webservices_2.0:1905:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:sap:commerce_webservices_2.0:1905:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_webservices_2.0:2005:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_webservices_2.0:2011:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_webservices_2.0:2105:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_webservices_2.0:2205:*:*:*:*:*:*:*
- Range: 1905, 2005, 2105, 2011, 2205
- Range: 1905
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.