CVE-2025-27431: Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java
User management functionality in SAP NetWeaver Application Server Java is vulnerable to Stored Cross-Site Scripting (XSS). This could enable an attacker to inject malicious payload that gets stored and executed when a user accesses the functionality, hence leading to information disclosure or unauthorized data modifications within the scope of victim�s browser. There is no impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27431?
CVE-2025-27431 has been classified as a medium severity vulnerability due to its potential for exploitation via stored XSS.
How do I fix CVE-2025-27431?
To mitigate CVE-2025-27431, ensure that your SAP NetWeaver Application Server Java is updated with the latest security patches provided by SAP.
What kinds of attacks can CVE-2025-27431 enable?
CVE-2025-27431 can enable attackers to perform stored cross-site scripting attacks, potentially leading to the theft of user information or session hijacking.
Who is affected by CVE-2025-27431?
Any organization using SAP NetWeaver Application Server Java is potentially affected by CVE-2025-27431.
What steps should I take to protect my application from CVE-2025-27431?
To protect your application from CVE-2025-27431, conduct regular security assessments and apply all recommended updates and patches from SAP.