AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-0057

MEDIUM · CVSS 4.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-01-14 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.8. It affects Java.

CVE
CVE-2025-0057
Severity
MEDIUM
CVSS
4.8
EPSS
0.23%
Java

Original NVD Description

SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.