Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This results in a limited impact on the confidentiality and integrity of user session information, while availability remains unaffected.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affected page. This results in a limited impact on the confidentiality and integrity of user session information, while availability remains unaffected. | |
| Title | Cross-Site Scripting (XSS) vulnerability in SAP Data Services (DQ Report) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-07-08T00:37:10.513Z
Updated: 2025-07-08T16:13:13.068Z
Reserved: 2025-04-16T13:25:45.231Z
Link: CVE-2025-42973
Updated: 2025-07-08T14:28:30.472Z
Status : Awaiting Analysis
Published: 2025-07-08T01:15:24.623
Modified: 2025-07-08T16:18:14.207
Link: CVE-2025-42973
No data.