Advisory
A note with CVSS 6.1 for component BC-CTS-DTR was released by SAP on 14.06.2022. The correction/advisory 3197927 was described with "[CVE-2022-29618] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Development Infrastructure (Design Time Repository)" and affects the system type SAP NetWeaver Development Infrastructure (NWDI).
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is cross-site scripting (xss) within SAP NetWeaver Development Infrastructure (NWDI).
Risk specification
SAP NetWeaver Design Time Repository (DTR) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Solution
The URL parameters are now properly encoded to prevent a successful XSS attack. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Cross-site scripting/request forgery filter engine on IDS/IPS/firewall systems. ".
