CVE-2025-26659: Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript payload executes in the scope of victim�s browser potentially compromising their data and/or manipulating browser content. This leads to a limited impact on confidentiality and integrity. There is no impact on availability
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26659?
CVE-2025-26659 is rated as a medium severity vulnerability due to the potential for exploitation via DOM-based Cross-Site Scripting.
How do I fix CVE-2025-26659?
To fix CVE-2025-26659, apply the latest security patch provided by SAP for the NetWeaver Application Server ABAP.
What are the risks associated with CVE-2025-26659?
Exploitation of CVE-2025-26659 can allow attackers to execute malicious scripts leading to data theft or session hijacking.
Who is affected by CVE-2025-26659?
CVE-2025-26659 affects users of the SAP NetWeaver Application Server ABAP that do not have the necessary security patches applied.
Can CVE-2025-26659 be exploited remotely?
Yes, CVE-2025-26659 can be exploited remotely by an attacker who can send crafted web messages to the application.