PT-2025-10673 · Sap · Sap Netweaver Application Server Abap

Published

2025-03-11

·

Updated

2025-03-11

·

CVE-2025-26659

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP (affected versions not specified)
Description The issue is related to a DOM-based Cross-Site Scripting (XSS) vulnerability. It occurs because the software does not sufficiently encode user-controlled inputs. This allows an attacker to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, a malicious JavaScript payload executes in the scope of the victim's browser, potentially compromising their data and/or manipulating browser content. The impact is limited to confidentiality and integrity, with no effect on availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03621
CVE-2025-26659

Affected Products

Sap Netweaver Application Server Abap