CVE Database
/

CVE-2022-35297

Back to search

CVE-2022-35297

Published: Oct 11, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.

VendorProductVersions

SAP SE

SAP Enable Now

affected
10

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now