CVE Database
/

CVE-2022-39799

Back to search

CVE-2022-39799

Published: Sep 13, 2022

Modified: Jun 10, 2025

PUBLISHED

Description

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

VendorProductVersions

SAP SE

SAP NetWeaver AS ABAP (SAP GUI for HTML within the Fiori Launchpad)

affected
KERNEL 7.77
affected
7.81
affected
7.85
affected
7.89
affected
7.54

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now