SAPCVE-2026-44762
SAP Data Services Management Console: clickjacking
Low3.7CVE-2026-44762 · Published Aug 11, 2026 · updated Aug 26, 2026
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within the application's context. Successful exploitation may result in a low impact on confidentiality and integrity, with no impact on the availability of the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP Data Services Management Console Product | <= SBOP_DS_MANAGEMENT_CONSOLE 4.3 | No fix yet |
| <= 2025 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1021
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | SAP Commerce Cloud (Data Hub Adapter): remote code execution | Critical10.0 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): improper signature check | Medium5.9 | No fix yet |
| Aug 11 | SAP Business AI Platform (Approuter): path traversal | Medium5.9 | No fix yet |
| Aug 11 | SAP Approuter does not sufficiently sanitize certain request headers before... | Medium5.3 | No fix yet |
| Aug 11 | SAP NetWeaver Application Server ABAP: cross-site scripting | Medium6.3 | No fix yet |
| Aug 11 | SAP BusinessObjects Business Intelligence Platform (Central : hard-coded key | High7.9 | No fix yet |