SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in the DS management console.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-38118 SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack, only few of the pages are vulnerable in the DS management console.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-03T09:29:17.458Z

Reserved: 2022-07-05T00:00:00

Link: CVE-2022-35226

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-10-11T21:15:12.937

Modified: 2024-11-21T07:10:55.890

Link: CVE-2022-35226

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.