CVE-2025-27431
11.03.2025, 01:15
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data modifications within the scope of victims browser. There is no impact on availability.
Awaiting analysis
This vulnerability is currently awaiting analysis.