CVE-2026-44746
Description
Reflected XSS in SAP NetWeaver JAVA's JDBC Test Servlet allows unauthenticated attackers to execute malicious scripts in victim browsers via crafted URLs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in SAP NetWeaver JAVA's JDBC Test Servlet allows unauthenticated attackers to execute malicious scripts in victim browsers via crafted URLs.
Vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in the JDBC Test Servlet component of SAP NetWeaver JAVA. This issue affects unauthenticated users. The vulnerability is triggered when an attacker crafts a URL containing malicious script input, which is then processed during web page generation.
Exploitation
An unauthenticated attacker can exploit this vulnerability by crafting a malicious URL and tricking a victim into clicking it. The attacker does not require any special privileges or network position beyond being able to send a URL to the victim. User interaction is required in the form of the victim clicking the crafted link.
Impact
Successful exploitation allows an attacker to execute arbitrary malicious content within the victim's browser. This can lead to the access and/or modification of information related to the web client, impacting the confidentiality and integrity of the application. There is no impact on availability.
Mitigation
SAP regularly releases security corrections via SAP Security Notes on their SAP Security Patch Day, scheduled for the second Tuesday of every month [1]. Customers are advised to implement these corrections at a priority. Specific details regarding the fixed version and release date for this particular vulnerability are not yet disclosed in the available references, but SAP Security Notes with low or medium priority contain corrections in at least the newest support package in all mainstream and extended maintenance releases [1].
AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2News mentions
1- SAP: Twelve Vulnerabilities Disclosed Together on June 9, 2026Vypr Intelligence · Jun 9, 2026