Skip to content
SAPCVE-2026-44760

SAP NetWeaver Application Server: cross-site scripting

Medium4.7CVE-2026-44760 · Published Jul 14, 2026

Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation could allow the attacker to steal session information, perform authenticated actions on behalf of the victim user etc. This vulnerability has low impact on confidentiality and integrity of the data and no impact on application 's availability.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)
Product
<= SAP_BASIS 700No fix yet
<= SAP_BASIS 701No fix yet
<= SAP_BASIS 702No fix yet
<= SAP_BASIS 731No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...
Critical9.1Jul 14
SAP @ui5/webcomponents-base: clickjacking
Medium6.1Jul 14
SAP CRM (WebClient UI): attacker could inject
Medium4.1Jul 14
SAP S/4HANA Project Management (PPM-PRO): SQL injection
Medium5.5Jul 14
SAP S/4 HANA (Create Single Payment): missing authorization
Medium4.3Jul 14
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.