SAP NetWeaver Application Server ABAP
cpe:2.3:a:sap:netweaver_application_server_abap:*:*:*:*:*:*:*, +1 more
A cross-site scripting vulnerability has been identified in SAP NetWeaver Application Server ABAP and ABAP Platform. This issue allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. When a victim clicks on this URL, the malicious payload is executed in their browser. Exploitation of this vulnerability enables the attacker to access or modify sensitive information within the context of the victim's web browser, without affecting the application's availability.
Successful exploitation allows access to or modification of sensitive information in the victim's web browser, without impacting the application's availability.
Users are advised to review and implement the SAP Security Note associated with this vulnerability. This can be done through the SAP for Me platform, where all Security Notes are available. For details on the SAP Security Patch Day and how to access Security Notes, refer to the SAP Security Notes FAQ.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.