Junglewise Threat Intelligence

CVE-2026-44757: SAP Wily Introscope Enterprise Manager XSS via crafted URL

CVE-2026-44757 · Severity: medium · CVSS 4.7 · Published 2026-06-09

Vendors: SAP.

Executive brief

SAP Wily Introscope Enterprise Manager, a tool used for monitoring application performance, is vulnerable to a security flaw where an attacker can trick a user into clicking a malicious link. If successful, this allows the attacker to run unauthorized scripts in the user's web browser. While this does not crash the system, it could allow an attacker to view or modify sensitive information within the user's active session.

Technical details

A cross-site scripting (XSS) vulnerability exists in SAP Wily Introscope Enterprise Manager due to improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can craft a malicious URL that, when visited by a victim, executes arbitrary script code in the context of the victim's browser session. The attack requires user interaction (clicking a link) and is classified with high attack complexity, likely due to specific environmental conditions or browser protections required for successful exploitation. The vulnerability impacts confidentiality and integrity but has no impact on system availability. SAP has released security notes to address this issue.

Affected products

  • SAP Wily Introscope Enterprise Manager

Timeline

  • 2026-06-09: advisory: Initial publication by SAP and NVD

References