Impact
The vulnerability is a code injection flaw in SAP NetWeaver Application Server Java's Web Dynpro Java component. An unauthenticated attacker can send crafted input that the application interprets and renders as attacker-controlled content. When a user accesses the affected functionality, the injected content may run in the victim’s browser, allowing arbitrary client-side code execution. This can compromise the confidentiality and integrity of the user session, but does not affect application availability.
Affected Systems
SAP NetWeaver Application Server Java, specifically the Web Dynpro Java module. No specific version numbers are disclosed, so all instances of this component should be reviewed for potential exposure.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. No publicly available exploit data or catalog listing is referenced. The vulnerability can be triggered by an unauthenticated user delivering malicious input and requires the victim to access the vulnerable functionality for the injected content to execute.
OpenCVE Enrichment