CVE-2026-0499: Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0499?
CVE-2026-0499 has a medium severity rating due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2026-0499?
To fix CVE-2026-0499, ensure that your SAP NetWeaver Enterprise Portal is updated to the latest security patch provided by SAP.
What is the impact of CVE-2026-0499?
CVE-2026-0499 allows an unauthenticated attacker to inject and execute malicious scripts in the user's browser.
Who is affected by CVE-2026-0499?
Any installation of SAP NetWeaver Enterprise Portal that does not have the latest security updates is affected by CVE-2026-0499.
Is authentication required to exploit CVE-2026-0499?
No, CVE-2026-0499 can be exploited by an unauthenticated attacker through crafted URL parameters.