CVE-2025-27431

User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data modifications within the scope of victim?s browser. There is no impact on availability.
Configurations

No configuration.

History

11 Mar 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 01:15

Updated : 2025-03-11 01:15


NVD link : CVE-2025-27431

Mitre link : CVE-2025-27431


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')