CVE-2022-29610

Description

SAP NetWeaver Application Server ABAP allows an authenticated attacker to upload malicious files and delete (theme) data, which could result in Stored Cross-Site Scripting (XSS) attack.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.37

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 753Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 754Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 755Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 756Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 753Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 754Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 755Windows
Multiple Vulnerabilities are affected in SAP NetWeaver and ABAP platform (ST-PI) 756Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234