PT-2022-25773 · Sap · Sap Financial Consolidation

CVE-2022-41260

·

Published

2022-11-08

·

Updated

2022-12-09

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Financial Consolidation version 1010
Description The issue arises from insufficient encoding of user-controlled input, allowing an unauthenticated attacker to inject a web script via a GET request. Successful exploitation can lead to an attacker viewing or modifying information, resulting in a limited impact on the confidentiality and integrity of the application.
Recommendations For SAP Financial Consolidation version 1010, update to a version that sufficiently encodes user-controlled input to prevent web script injection via GET requests. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-41260

Affected Products

Sap Financial Consolidation