Description
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within the application's context. Successful exploitation may result in a low impact on confidentiality and integrity, with no impact on the availability of the application.
Published: 2026-08-11
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the SAP Data Services Management Console’s default CSP settings, which are overly permissive and missing critical directives. An authenticated attacker who can already log into the console could exploit this weakness in combination with a secondary flaw to inject and run malicious scripts in the application. The impact on confidentiality and integrity is considered low: the attacker may achieve limited data exfiltration or persistence within the console’s context, but the application’s availability remains unaffected.

Affected Systems

SAP Data Services Management Console is the affected product. No specific version range is listed, so all releases of the console are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 3.7 places the flaw in the low‑severity range, and the EPSS score is not available, indicating little known evidence of exploitation. The attack requires both authentication and a combination with another vulnerability, reducing the likelihood of successful exploitation. Because the flaw is not listed in the CISA KEV catalog, a known, widespread exploitation is not reported at this time. Nevertheless, the presence of the CSP misconfiguration coupled with another vulnerability means administrators should treat this as a medium‑risk concern for systems exposed to insider or elevated‑role threats.

Generated by OpenCVE AI on August 11, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update detailed in SAP Note 3739913 to enforce stricter CSP directives in the Management Console.
  • Verify that the console’s CSP no longer permits unrestricted script sources; add explicit source restrictions such as 'default-src' and 'script-src' for trusted origins.
  • Review and reduce privileges for users who have access to the Management Console, ensuring that only those with a legitimate need retain elevated roles.

Generated by OpenCVE AI on August 11, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Data Services Management Console
Vendors & Products Sap Se
Sap Se sap Data Services Management Console

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Description SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within the application's context. Successful exploitation may result in a low impact on confidentiality and integrity, with no impact on the availability of the application.
Title Security Misconfiguration in SAP Data Services Management Console
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Sap Se Sap Data Services Management Console
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-08-11T14:33:08.419Z

Reserved: 2026-05-07T18:31:04.067Z

Link: CVE-2026-44762

cve-icon Vulnrichment

Updated: 2026-08-11T14:33:03.800Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T01:17:20.800

Modified: 2026-08-26T19:00:14.450

Link: CVE-2026-44762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:21:12Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames