Junglewise Threat Intelligence

CVE-2026-44746: SAP NetWeaver JAVA reflected XSS in JDBC Test Servlet

CVE-2026-44746 · Severity: medium · CVSS 6.1 · Published 2026-06-09

Technologies: SAP Netweaver Application Server Java. Vendors: SAP.

Executive brief

SAP NetWeaver JAVA, a foundational platform for running SAP applications, contains a security flaw in its JDBC Test Servlet. An attacker could trick a user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's web browser. This could lead to the theft of session information or the unauthorized modification of data within the user's active session.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the JDBC Test Servlet component of SAP NetWeaver JAVA. The vulnerability stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by crafting a malicious URL and enticing a victim to click it. Upon execution, the malicious script runs within the context of the victim's browser session, potentially allowing the attacker to access or modify sensitive web client information, such as session tokens or application data. The attack requires user interaction and has a CVSS base score of 6.1, impacting confidentiality and integrity.

Affected products

  • SAP NetWeaver JAVA (JDBC Test Servlet)

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats