Web: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-39799

Sept. 13, 2022, 4:15 p.m. |

National Vulnerability Database nist.gov

An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

cve

Cybersecurity Engineer

@ Apercen Partners LLC | Folsom, CA

IDM Sr. Security Developer

@ The Ohio State University | Columbus, OH, United States

IT Security Engineer

@ Stylitics | New York City

Information Security Engineer

@ VDA Labs | Remote

Information Security Analyst

@ Metropolitan Transportation Commission | San Francisco, CA

IT Security Manager - Stamford or Middletown Location

@ Charles IT | Middletown, Connecticut, United States

Cyber Security Analyst - Sr. Consultant Level

@ Visa | Ashburn, VA, United States

Staff Information Security Engineer

@ ServiceNow | Atlanta, Georgia, United States

Senior Compliance Program Manager

@ Zscaler | San Jose, CA, United States

Supervisor, F&I Trainer and Compliance Financial Services

@ Lucid Motors | Newark, CA

Senior Information Security Analyst

@ RecargaPay | São Paulo, State of São Paulo, Brazil - Remote

IT Security Engineer - Middletown Location

@ Charles IT | Middletown, Connecticut, United States