SAP NetWeaver Application Server ABAP Cross-Site Scripting Vulnerability

Vulnerability

A Cross-Site Scripting (XSS) vulnerability has been identified in SAP NetWeaver Application Server ABAP. This issue allows malicious scripts to be executed within the application. While the vulnerability does not affect the application's availability, it could have minor implications for its confidentiality and integrity.

Impact

Exploitation of this vulnerability could lead to Cross-Site Scripting (XSS) attacks, allowing for the execution of malicious scripts in the context of the user's session.

Remediation

Users are advised to review and implement the SAP Security Notes available in SAP for Me. Security fixes for SAP NetWeaver based products are delivered with the support packages. For information on the latest SAP Security Patch Day, refer to the SAP Security Patch Day Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
1.7
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.