{ "id": "CVE-2022-29618", "sourceIdentifier": "cna@sap.com", "published": "2022-06-14T19:15:07.550", "lastModified": "2024-11-21T06:59:26.637", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Due to insufficient input validation, SAP NetWeaver Development Infrastructure (Design Time Repository) - versions 7.30, 7.31, 7.40, 7.50, allows an unauthenticated attacker to inject script into the URL and execute code in the user\u2019s browser. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality and integrity of the application." }, { "lang": "es", "value": "Debido a una insuficiente comprobaci\u00f3n de entrada, SAP NetWeaver Development Infrastructure (Design Time Repository) - versiones 7.30, 7.31, 7.40, 7.50, permite a un atacante no autenticado inyectar un script en la URL y ejecutar c\u00f3digo en el navegador del usuario. Si se explota con \u00e9xito, un atacante puede ver o modificar informaci\u00f3n causando un impacto limitado en la confidencialidad e integridad de la aplicaci\u00f3n" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE" }, "exploitabilityScore": 2.8, "impactScore": 2.7 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "baseScore": 4.3, "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE" }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "cna@sap.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:sap:netweaver_development_infrastructure:7.30:*:*:*:*:*:*:*", "matchCriteriaId": "A6461DE2-4828-4A7C-B8B0-DC3E4AD2EEA9" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sap:netweaver_development_infrastructure:7.31:*:*:*:*:*:*:*", "matchCriteriaId": "DFA0B55C-B687-4E13-ADC9-5F1A2059DA6F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sap:netweaver_development_infrastructure:7.40:*:*:*:*:*:*:*", "matchCriteriaId": "0ACDCB10-87D1-46F1-B244-E4930B53BC92" }, { "vulnerable": true, "criteria": "cpe:2.3:a:sap:netweaver_development_infrastructure:7.50:*:*:*:*:*:*:*", "matchCriteriaId": "88555DEC-8AEC-45EE-80BF-C1CE58DE3374" } ] } ] } ], "references": [ { "url": "https://launchpad.support.sap.com/#/notes/3197927", "source": "cna@sap.com", "tags": [ "Permissions Required", "Vendor Advisory" ] }, { "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html", "source": "cna@sap.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://launchpad.support.sap.com/#/notes/3197927", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Permissions Required", "Vendor Advisory" ] }, { "url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }