CyberRota Analysis
AI-GeneratedSAP NetWeaver Enterprise Portal is vulnerable to reflected cross-site scripting (XSS) attacks, allowing unauthenticated attackers to inject malicious scripts via URL parameters. This can lead to session information theft, content manipulation, or user redirection, posing a medium risk to the application's confidentiality and integrity. Organizations using this platform should prioritize patching to mitigate potential exploitation risks.
Original NVD Description
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.