Impact
The CVE describes a reflected Cross‑Site Scripting flaw in the Configuration Wizard of SAP NetWeaver Application Server Java. An attacker can craft a URL that injects JavaScript, which then executes in the victim’s browser when the URL is visited. If the user is authenticated, the script can read cookies with session tokens and other sensitive client‑side information, thereby supporting session hijacking or other forms of data exfiltration. The vulnerability also enables an attacker to change non‑sensitive data shown in the client view. The weakness is a classic input‑validation issue identified by CWE‑79, leading to high confidentiality impact with low integrity and no availability impact.
Affected Systems
The affected product is SAP NetWeaver Application Server Java, specifically the Configuration Wizard component exposed via HTTP(S). All installations of this component that have not applied the relevant SAP security patch are vulnerable. No specific version numbers are listed in the CNA data, so any unpatched deployments of the Configuration Wizard remain at risk.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity vulnerability. Because the bug can be triggered by any unauthenticated user who can access the wizard URL, an attacker can exploit it from any network that reaches the endpoint, for example by embedding the malicious link in an email or a web page. The EPSS score is less than 1%, suggesting the overall exploitation probability is low at present, and the vulnerability is not listed in CISA KEV, meaning no known active exploits. Nonetheless, the risk of unintended session theft remains significant and warrants prompt remediation.
OpenCVE Enrichment