PT-2025-20804 · Sap Se · Sap Data Services Management Console

Published

2025-05-13

·

Updated

2025-05-13

·

CVE-2025-26662

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined.
Description The issue concerns insufficient encoding of user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on a compromised link, the injected script gets executed within the scope of the victim's browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-26662

Affected Products

Sap Data Services Management Console