Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14356 | The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted. |
Tue, 13 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted. | |
| Title | Cross-Site Scripting (XSS) vulnerability in the SAP Data Services Management Console | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-11-07T05:03:29.249Z
Reserved: 2025-02-12T21:05:31.736Z
Link: CVE-2025-26662
Updated: 2025-05-13T14:06:44.912Z
Status : Deferred
Published: 2025-05-13T01:15:47.243
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-26662
No data.
OpenCVE Enrichment
No data.
EUVD