CVE-2022-39799

Publication date

2022-09-13 15:43:40

Family

sap

State

PUBLISHED

Description

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.