VYPR
Medium severity4.8NVD Advisory· Published Sep 10, 2024· Updated Apr 15, 2026

CVE-2024-45280

CVE-2024-45280

Description

Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integrity of the application. There is no impact on availability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stored cross-site scripting vulnerability in SAP NetWeaver AS Java allows attacker-controlled scripts in the login application, affecting confidentiality and integrity.

Vulnerability

Description

CVE-2024-45280 is a stored cross-site scripting vulnerability affecting SAP NetWeaver AS Java. The root cause is insufficient encoding of user-controlled inputs within the login application, which allows attackers to inject arbitrary script code [1]. This is classified as a medium-severity issue with a CVSS v3 score of 4.8.

Exploitation

Context

To exploit this vulnerability, an attacker must be able to submit crafted input that is subsequently stored and rendered in the login application without proper sanitization. The attack does not require authentication from the attacker's perspective, but relies on a victim user (such as an administrator) accessing the maliciously crafted content [1]. The network attack vector is likely remote, as the login application is typically exposed on the network.

Impact

Assessment

Successful exploitation allows the attacker to execute malicious scripts in the context of the affected user's session. This leads to a limited compromise of confidentiality (e.g., disclosure of session tokens or other sensitive data visible to the script) and integrity (e.g., modification of the displayed content or the ability to perform actions on behalf of the victim). Availability of the application is not impacted [1].

Remediation

Status

SAP has released a security patch for this vulnerability, which is available via the SAP Security Notes process. Administrators are strongly advised to apply the provided correction as part of regular patch day maintenance [1]. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.