SAP NetWeaver Application Server ABAP CSS Injection Vulnerability

Vulnerability

A vulnerability in SAP NetWeaver Application Server ABAP allows for the injection of custom Cascading Style Sheets (CSS) into web pages served by the application. This issue arises from improper input handling under certain conditions. When a user accesses the affected page, the injected CSS is executed. While this vulnerability has a low impact on confidentiality, it does not affect integrity or availability.

Impact

Exploitation of this vulnerability allows for the injection and execution of custom CSS, which could be used to manipulate the appearance of the web page or potentially exploit other vulnerabilities, such as Cross-Site Scripting (XSS).

Remediation

Users are advised to consult the SAP Security Notes for guidance on applying patches or updates. Security fixes for SAP NetWeaver based products are delivered with the support packages. For information on the latest SAP Security Patch Day, refer to the SAP Security Patch Day Bulletin.

Added: May 14, 2026, 7:40 PM
Updated: May 14, 2026, 7:40 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
1.0
exploitability
4.6
remediation
6.0
relevance
8.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.