SAP NetWeaver Application Server ABAP
cpe:2.3:a:sap:netweaver_application_server_abap:*:*:*:*:*:*:*
A stored cross-site scripting vulnerability has been identified in SAP NetWeaver Application Server ABAP. The issue arises because the application does not properly encode user-controlled inputs, allowing an attacker to inject malicious JavaScript into a website. This injected script is executed when a user visits the compromised page, potentially compromising the confidentiality and integrity of the user's browser session.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user visiting the affected page.
Users are advised to review and implement the SAP Security Note associated with this vulnerability. This can be done through the SAP for Me platform, specifically during the monthly SAP Security Patch Day.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.