PT-2025-6119 · Sap · Sap Netweaver Application Server Java
Published
2025-02-10
·
Updated
2025-02-12
·
CVE-2025-0054
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP NetWeaver Application Server Java versions prior to the fixed version
Description:
The issue is related to insufficient handling of user input, resulting in a stored cross-site scripting vulnerability. Attackers with basic user privileges can store a Javascript payload on the server, which could be later executed in the victim's web browser, potentially allowing them to read or modify information associated with the vulnerable web page.
Recommendations:
For SAP NetWeaver Application Server Java, update to a version that includes the fix for this issue to prevent exploitation.
As a temporary workaround, consider restricting access to sensitive web pages and implementing additional security measures to minimize the risk of stored cross-site scripting attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver Application Server Java