Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19722 | The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability. |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability. | The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability. |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 10 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Application Server Java |
|
| CPEs | cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap netweaver Application Server Java |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-02-11T04:13:01.325Z
Reserved: 2024-01-05T10:21:35.256Z
Link: CVE-2024-22126
Updated: 2024-08-01T22:35:34.804Z
Status : Modified
Published: 2024-02-13T02:15:08.107
Modified: 2025-02-11T05:15:13.300
Link: CVE-2024-22126
No data.
OpenCVE Enrichment
No data.
EUVD