Executive brief
SAP NetWeaver Application Server, a core platform for running business applications, is affected by a security flaw in its Business Server Pages framework. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of login sessions or the performance of unauthorized actions on behalf of the victim.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Business Server Pages (BSP) framework of SAP NetWeaver Application Server ABAP. The root cause is the failure of the framework to properly sanitize input before reflecting it back into the HTTP response. An unauthenticated remote attacker can exploit this by inducing a user to interact with a specially crafted URL. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking (CWE-79). The vulnerability affects multiple SAP_BASIS versions ranging from 700 to 920. Fixes are typically delivered via SAP Security Notes and Support Packages.
Affected products
- SAP NetWeaver Application Server ABAP (Business Server Pages) SAP_BASIS 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 919, 920
Timeline
- 2026-07-14: advisory: Published as part of SAP Security Patch Day