cbcvebase.
CVE-2022-29618
published 2022-06-14

CVE-2022-29618: Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user’s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application.

Affected

8 ranges
VendorProductVersion rangeFixed in
sapnetweaver_development_infrastructure
sapnetweaver_development_infrastructure
sapnetweaver_development_infrastructure
sapnetweaver_development_infrastructure
sap_sesap_netweaver_development_infrastructure
sap_sesap_netweaver_development_infrastructure
sap_sesap_netweaver_development_infrastructure
sap_sesap_netweaver_development_infrastructure