« Volver al listado

CVE-2022-24397

Estado: ModificadaMedia (6.1)—

SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-24397",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver Enterprise Portal",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.30"
            },
            {
              "status": "affected",
              "version": "< 7.31"
            },
            {
              "status": "affected",
              "version": "< 7.40"
            },
            {
              "status": "affected",
              "version": "< 7.50"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-03-10T17:46:10.087",
  "references": [
    {
      "url": "https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/3146260",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/3146260",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in reflected Cross-Site Scripting (XSS) vulnerability.This reflected cross-site scripting attack can be used to non-permanently deface or modify displayed content of portal Website. The execution of the script content by a victim registered on the portal could compromise the confidentiality and integrity of victim’s web browser."
    },
    {
      "lang": "es",
      "value": "SAP NetWeaver Enterprise Portal - versiones 7.30, 7.31, 7.40, 7.50, no codifica suficientemente las entradas controladas por el usuario, resultando en una vulnerabilidad de tipo cross-Site Scripting (XSS) reflejado. La ejecución del contenido del script por parte de una víctima registrada en el portal podría comprometer la confidencialidad e integridad del navegador web de la víctima"
    }
  ],
  "lastModified": "2026-06-17T04:31:45.923",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver_enterprise_portal:7.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64F0B5E2-054F-41CC-9296-38E3E5DFC77B"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_enterprise_portal:7.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E666D8FD-1F21-4E97-80BB-D560AB125DB5"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_enterprise_portal:7.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D61E5F0-5F16-489D-BB7D-2C630637DCAC"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_enterprise_portal:7.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D91F9D76-39D6-4D5E-BFAE-892CB8C30A79"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}