PT-2025-10677 · Sap · Sap Netweaver Application Server Java

Published

2025-03-11

·

Updated

2025-03-11

·

CVE-2025-27431

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server Java (affected versions not specified)
Description The user management functionality is susceptible to Stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious payload. This could lead to information disclosure or unauthorized data modifications within the scope of the victim's browser when the functionality is accessed. There is no impact on availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03628
CVE-2025-27431

Affected Products

Sap Netweaver Application Server Java