Unrated severityNVD Advisory· Published Jul 14, 2026· Updated Jul 14, 2026
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)
CVE-2026-44752
Description
SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.