Executive brief
A vulnerability in SAP NetWeaver Application Server Java could allow an attacker to trick a user's browser into executing malicious code. This occurs when the application improperly handles user input within the Web Dynpro Java component. If successful, an attacker could compromise a user's session, potentially leading to unauthorized access to sensitive information or the ability to perform actions on the user's behalf.
Technical details
A code injection vulnerability (CWE-94) exists in the Web Dynpro Java component of SAP NetWeaver Application Server Java. The flaw stems from improper validation of user-supplied input, which allows an unauthenticated remote attacker to provide crafted content that the application subsequently references. When a victim interacts with the affected functionality, the attacker-controlled content is executed within the context of the victim's browser session. This can lead to session hijacking and the execution of arbitrary client-side scripts. The vulnerability has been identified in version 7.50, and SAP has released security notes to address the issue.
Affected products
- SAP NetWeaver Application Server Java (Web Dynpro Java) 7.50
Timeline
- 2026-04-13: disclosed
- 2026-04-14: advisory