CVE-2025-0057: Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application)
SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0057?
CVE-2025-0057 has a high severity rating due to the potential impact of stored cross-site scripting.
How do I fix CVE-2025-0057?
To fix CVE-2025-0057, apply the latest security patches provided by SAP for NetWeaver AS JAVA.
Who is affected by CVE-2025-0057?
Organizations using SAP NetWeaver AS JAVA are affected by CVE-2025-0057.
What type of vulnerability is CVE-2025-0057?
CVE-2025-0057 is classified as a stored cross-site scripting vulnerability.
What can an attacker do with CVE-2025-0057?
An attacker can upload malicious JavaScript content that may be executed in the browser of a victim who visits the affected application.