Количество 3
Количество 3
CVE-2025-42973
Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This results in a limited impact on the confidentiality and integrity of user session information, while availability remains unaffected.
GHSA-9pcp-9h99-jjxj
Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This results in a limited impact on the confidentiality and integrity of user session information, while availability remains unaffected.
BDU:2025-10648
Уязвимость приложения для интеграции и преобразования данных SAP Data Services, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-42973 Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This results in a limited impact on the confidentiality and integrity of user session information, while availability remains unaffected. | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад | |
GHSA-9pcp-9h99-jjxj Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This results in a limited impact on the confidentiality and integrity of user session information, while availability remains unaffected. | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад | |
BDU:2025-10648 Уязвимость приложения для интеграции и преобразования данных SAP Data Services, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю выполнить произвольный код | CVSS3: 5.4 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу