PT-2025-6119 · Sap · Sap Netweaver Application Server Java

Published

2025-02-10

·

Updated

2025-02-12

·

CVE-2025-0054

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver Application Server Java versions prior to the fixed version
Description: The issue is related to insufficient handling of user input, resulting in a stored cross-site scripting vulnerability. Attackers with basic user privileges can store a Javascript payload on the server, which could be later executed in the victim's web browser, potentially allowing them to read or modify information associated with the vulnerable web page.
Recommendations: For SAP NetWeaver Application Server Java, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to sensitive web pages and implementing additional security measures to minimize the risk of stored cross-site scripting attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-02759
CVE-2025-0054

Affected Products

Sap Netweaver Application Server Java