Executive brief
SAP Data Services Management Console has a weak Content Security Policy (CSP) configuration that lacks certain protective restrictions. An authenticated attacker could exploit this weakness in combination with other vulnerabilities to inject and execute malicious scripts within the application, potentially compromising the confidentiality and integrity of data processed by the console.
Technical details
This vulnerability involves an overly permissive Content Security Policy configuration in SAP Data Services Management Console that lacks certain restrictive directives. The weakness is a configuration/architecture issue rather than a classic code-level flaw. Exploitation requires both authentication and a secondary vulnerability to be present, as the CSP weakness alone does not allow immediate code execution. An authenticated malicious user could leverage this CSP misconfiguration to inject and execute arbitrary scripts within the application's security context, potentially accessing or modifying sensitive data. The impact on confidentiality and integrity is low, with no availability impact. SAP has issued a security note (SAP Note 3739913) with patches available as of the August 11, 2026 patch day.
Affected products
- SAP Data Services Management Console
Timeline
- 2026-08-11: disclosed