CyberRota Analysis
AI-GeneratedThe vulnerability affects applications using the Business Server Pages framework in SAP NetWeaver Application Server ABAP, allowing for Cross-Site Scripting (XSS) due to unsanitized input in HTTP responses. Attackers can exploit this flaw to inject and execute arbitrary JavaScript, potentially leading to session hijacking and unauthorized actions on behalf of users. Organizations utilizing this framework should prioritize remediation to mitigate risks associated with user data and session security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation could allow the attacker to steal session information, perform authenticated actions on behalf of the victim user etc. This vulnerability has low impact on confidentiality and integrity of the data and no impact on application 's availability.