SAP NetWeaver Enterprise Portal Cross-Site Scripting Vulnerability

Vulnerability

A Cross-Site Scripting (XSS) vulnerability has been identified in SAP NetWeaver Enterprise Portal. This vulnerability allows an unauthenticated attacker to inject malicious scripts that execute in the context of other users' browsers. Consequently, the attacker could steal session cookies, tokens, and other sensitive information. The vulnerability affects several different versions and/or ranges.

Impact

Exploitation of this vulnerability could lead to Cross-Site Scripting, allowing for the injection of malicious scripts that could be executed in the context of other users' browsers.

Remediation

Security fixes for SAP NetWeaver based products are delivered with the support packages. For information on the latest security patches, refer to the SAP Security Patch Day Notes.

Added: Dec 9, 2025, 7:33 PM
Updated: Dec 9, 2025, 7:33 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
4.2
exploitability
6.4
remediation
6.0
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.