Security Advisory

CVE-2022-41258

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-11-08 00:00:00
Last updated 2025-05-01 13:48:56
Assigner sap
State PUBLISHED

Description

Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to inject malicious script when running a common query in the Web Administration Console. On successful exploitation, an attacker can view or modify information causing a limited impact on confidentiality, integrity and availability of the application.