Impact
The vulnerability resides in the SAP Data Services Management Console’s default CSP settings, which are overly permissive and missing critical directives. An authenticated attacker who can already log into the console could exploit this weakness in combination with a secondary flaw to inject and run malicious scripts in the application. The impact on confidentiality and integrity is considered low: the attacker may achieve limited data exfiltration or persistence within the console’s context, but the application’s availability remains unaffected.
Affected Systems
SAP Data Services Management Console is the affected product. No specific version range is listed, so all releases of the console are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 3.7 places the flaw in the low‑severity range, and the EPSS score is not available, indicating little known evidence of exploitation. The attack requires both authentication and a combination with another vulnerability, reducing the likelihood of successful exploitation. Because the flaw is not listed in the CISA KEV catalog, a known, widespread exploitation is not reported at this time. Nevertheless, the presence of the CSP misconfiguration coupled with another vulnerability means administrators should treat this as a medium‑risk concern for systems exposed to insider or elevated‑role threats.
OpenCVE Enrichment