Junglewise Threat Intelligence

CVE-2026-44760: SAP NetWeaver AS ABAP Cross-Site Scripting in Business Server Pages

CVE-2026-44760 · Severity: medium · CVSS 4.7 · Published 2026-07-14

Technologies: SAP NetWeaver Application Server ABAP. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server, a core platform for running business applications, is affected by a security flaw in its Business Server Pages framework. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of login sessions or the performance of unauthorized actions on behalf of the victim.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Business Server Pages (BSP) framework of SAP NetWeaver Application Server ABAP. The root cause is the failure of the framework to properly sanitize input before reflecting it back into the HTTP response. An unauthenticated remote attacker can exploit this by inducing a user to interact with a specially crafted URL. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking (CWE-79). The vulnerability affects multiple SAP_BASIS versions ranging from 700 to 920. Fixes are typically delivered via SAP Security Notes and Support Packages.

Affected products

  • SAP NetWeaver Application Server ABAP (Business Server Pages) SAP_BASIS 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 919, 920

Timeline

  • 2026-07-14: advisory: Published as part of SAP Security Patch Day

References

Related threats