Advisory
A note with CVSS 6.1 for component BC-CTS-DTR was released by SAP on 14.06.2022. The correction/advisory 3197927 was described with "[CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)" and affects the system type SAP NetWeaver Development Infrastructure (NWDI).
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is cross-site scripting (xss) within SAP NetWeaver Development Infrastructure (NWDI).
Risk specification
SAP NetWeaver Design Time Repository (DTR) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.Solution
The URL parameters are now properly encoded to prevent a successful XSS attack. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Cross-site scripting/request forgery filter engine on IDS/IPS/firewall systems. ".
- 8.3 [CVE-2022-27656] Cross-Site Scripting (XSS) vulnerability in administration UI of SAP Webdispatcher and SAP Netweaver AS for ABAP and Java (ICM)
- 6.1 [CVE-2023-26457] Cross-Site Scripting (XSS) vulnerability in SAP Content Server
- 6.1 [CVE-2023-0021] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
- 5.4 [CVE-2022-29610] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
- 5.4 [CVE-2024-47594] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal (KMC)