Логотип exploitDog
bind:CVE-2026-0499
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-0499

Количество 3

Количество 3

nvd логотип

CVE-2026-0499

23 дня назад

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-jmwc-hm8x-6w23

23 дня назад

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2026-00763

24 дня назад

Уязвимость программной интеграционной платформы SAP NetWeaver Enterprise Portal, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-0499

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.

CVSS3: 6.1
0%
Низкий
23 дня назад
github логотип
GHSA-jmwc-hm8x-6w23

SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.

CVSS3: 6.1
0%
Низкий
23 дня назад
fstec логотип
BDU:2026-00763

Уязвимость программной интеграционной платформы SAP NetWeaver Enterprise Portal, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.1
0%
Низкий
24 дня назад

Уязвимостей на страницу