Impact
A reflected Cross‑Site Scripting flaw exists in Business Server Pages applications of SAP NetWeaver Application Server ABAP. Unsanitized input is incorporated into HTTP responses, allowing an attacker to inject and execute arbitrary JavaScript. Through this mechanism an adversary can steal session cookies or perform authenticated actions on behalf of the user. The weakness is classified as CWE‑79 and, while it has a low score on confidentiality and integrity impacts, it permits serious credential theft and unauthorized activity.
Affected Systems
The vulnerability impacts SAP NetWeaver Application Server ABAP, specifically applications built on the Business Server Pages framework. No specific version numbers are listed in the advisory; the issue is addressed by SAP Note 3754659.
Risk and Exploitability
The CVSS score of 4.7 indicates a low overall severity, and the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attacks rely on crafted URL parameters or form inputs that are later reflected in responses, meaning they typically require user interaction with a malicious link or page. Given its low CVSS but potential for session hijacking, the risk to organizations is moderate and should be mitigated promptly.
OpenCVE Enrichment