VYPR

Data Services Management

by SAP

CVEs (5)

  • CVE-2022-35226MedOct 11, 2022
    risk 0.40cvss 6.1epss 0.01

    SAP Data Services Management allows an attacker to copy the data from a request and echoed into the application's immediate response, it will lead to a Cross-Site Scripting vulnerability. The attacker would have to log in to the management console to perform such as an attack,…

  • CVE-2025-42973MedJul 8, 2025
    risk 0.35cvss 5.4epss 0.00

    Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when…

  • CVE-2018-2466MedOct 9, 2018
    risk 0.35cvss 5.4epss 0.01

    In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate user-controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.

  • CVE-2025-26662MedMay 13, 2025
    risk 0.29cvss 4.4epss 0.00

    The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of…

  • CVE-2026-44762LowAug 11, 2026
    risk 0.24cvss 3.7epss 0.00

    SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject…