CVE-2026-44759: Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2026-44759?
CVE-2026-44759 is a Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal that allows attackers to inject malicious scripts via a URL parameter.
What is the severity of CVE-2026-44759?
The severity of CVE-2026-44759 is classified as medium with a score of 6.1.
How can I fix CVE-2026-44759?
To fix CVE-2026-44759, it is recommended to apply the latest security updates and patches from SAP.
Who is affected by CVE-2026-44759?
CVE-2026-44759 affects users of SAP NetWeaver Enterprise Portal who could potentially fall victim to XSS attacks.
What are the potential impacts of CVE-2026-44759?
The potential impacts of CVE-2026-44759 include theft of session information and manipulation of the portal content.