Impact
Affected users who are authenticated in SAP NetWeaver Application Server ABAP can create malicious URLs that contain injected code. The code is reflected into the Document Object Model when a victim, also authenticated, accesses the link, allowing the attacker to run arbitrary scripts in the victim’s browser. The vulnerability is a classic reflected XSS flaw (CWE‑79) that can compromise confidentiality by stealing user data or credentials, while having a low impact on integrity and no effect on availability.
Affected Systems
SAP NetWeaver Application Server ABAP. No specific version information is provided.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time. The attack requires an authenticated attacker to create the malicious link and a victim user to be authenticated when accessing it, which limits the attack surface but still poses a non‑negligible threat, especially in environments where user credentials are reused or where link sharing is possible.
OpenCVE Enrichment