Vulnerabilities > CVE-2022-26101 - Unspecified vulnerability in SAP Fiori Launchpad 754/755/756
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
References
- http://packetstormsecurity.com/files/167561/SAP-Fiori-Launchpad-Cross-Site-Scripting.html
- http://packetstormsecurity.com/files/167561/SAP-Fiori-Launchpad-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2022/Jun/39
- http://seclists.org/fulldisclosure/2022/Jun/39
- https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10
- https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10
- https://launchpad.support.sap.com/#/notes/3149805
- https://launchpad.support.sap.com/#/notes/3149805