Loading HuntDB...

GHSA-vwhx-5rv8-vg6x

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenticated attacker to inject a script into a web request header. On successful exploitation, an attacker can view or modify information causing a limited impact on the confidentiality and integrity of the application.

Related CVEs

Key Information

GHSA ID
GHSA-vwhx-5rv8-vg6x
Published
December 13, 2022 12:30 AM
Last Modified
December 15, 2022 6:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.