CVE-2026-44746
Awaiting Analysis Awaiting Analysis - Queue
Reflected XSS in SAP NetWeaver JAVA JDBC Test Servlet

Publication date: 2026-06-09

Last updated on: 2026-06-09

Assigner: SAP SE

Description
Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a malicious script. If a victim clicks this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser. This could allow the attacker to access and/or modify information related to the webclient, impacting the confidentiality and integrity of the application, with no impact to availability.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-09
Last Modified
2026-06-09
Generated
2026-06-09
AI Q&A
2026-06-09
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
sap netweaver_java *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a reflected cross-site scripting (XSS) issue found in SAP NetWeaver JAVA's JDBC Test Servlet. An attacker who is not authenticated can create a specially crafted URL containing malicious script code. When a victim clicks on this URL, the malicious script is executed in the victim's browser because the input is reflected and processed during the web page generation.

Impact Analysis

The impact of this vulnerability includes the attacker being able to execute malicious scripts in the victim's browser. This can lead to unauthorized access to or modification of information related to the web client, thereby compromising the confidentiality and integrity of the application. However, this vulnerability does not affect the availability of the system.

Compliance Impact

This vulnerability can impact compliance with standards and regulations such as GDPR and HIPAA because it compromises the confidentiality and integrity of information handled by the application. Unauthorized access or modification of sensitive data due to the XSS vulnerability could lead to violations of data protection requirements mandated by these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44746. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart