Vulnerability CVE-2022-39799


Published: 2022-09-13

Description:
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://launchpad.support.sap.com/#/notes/3229820
https://github.com/cla-assistant/cla-assistant/security/advisories/GHSA-jjjv-grgr-v8h3

Copyright 2026, cxsecurity.com

 

Back to Top