CVE-2026-44746
Awaiting Analysis Awaiting Analysis - Queue

Reflected XSS in SAP NetWeaver JAVA JDBC Test Servlet

Vulnerability report for CVE-2026-44746, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: SAP SE

Description

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser. This could allow the attacker to access and/or modify information related to the webclient, impacting the confidentiality and integrity of the application, with no impact to availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-29
AI Q&A
2026-06-09
EPSS Evaluated
2026-06-28
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_java *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a reflected cross-site scripting (XSS) issue found in SAP NetWeaver JAVA's JDBC Test Servlet. An attacker who is not authenticated can create a specially crafted URL containing malicious script code. When a victim clicks on this URL, the malicious script is executed in the victim's browser because the input is reflected and processed during the web page generation.

Impact Analysis

The impact of this vulnerability includes the attacker being able to execute malicious scripts in the victim's browser. This can lead to unauthorized access to or modification of information related to the web client, thereby compromising the confidentiality and integrity of the application. However, this vulnerability does not affect the availability of the system.

Compliance Impact

This vulnerability can impact compliance with standards and regulations such as GDPR and HIPAA because it compromises the confidentiality and integrity of information handled by the application. Unauthorized access or modification of sensitive data due to the XSS vulnerability could lead to violations of data protection requirements mandated by these regulations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44746. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart