SAP NetWeaver Enterprise Portal
cpe:2.3:a:sap:netweaver_enterprise_portal:*:*:*:*:*:*:*
A Cross-Site Scripting (XSS) vulnerability has been identified in SAP NetWeaver Enterprise Portal. This vulnerability allows an unauthenticated attacker to inject malicious scripts that execute in the context of other users' browsers. Consequently, the attacker could steal session cookies, tokens, and other sensitive information. The vulnerability affects several different versions and/or ranges.
Exploitation of this vulnerability could lead to Cross-Site Scripting, allowing for the injection of malicious scripts that could be executed in the context of other users' browsers.
Security fixes for SAP NetWeaver based products are delivered with the support packages. For information on the latest security patches, refer to the SAP Security Patch Day Notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.