CVE Published: 11/10/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: sap |
Vendor: SAP SE |
Product: SAP Enable Now Status : PUBLISHED
CVE-2022-35297 Description
The application SAP Enable Now does not sufficiently encode user-controlled inputs over the network before it is placed in the output being served to other users, thereby expanding the attack scope, resulting in Stored Cross-Site Scripting (XSS) vulnerability leading to limited impact on Confidentiality, Integrity and Availability.