Enterprise & Mobile
Remote Code Execution
Code Injection Vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
This vulnerability allows a remote, unauthenticated attacker to execute arbitrary client-side code in the browsers of users accessing the affected SAP NetWeaver functionality.
.png)
Overview
SAP NetWeaver Application Server Java (Web Dynpro Java) contains a Code Injection vulnerability that allows an unauthenticated attacker to supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content. If a victim accesses the affected functionality, that attacker-controlled content could be executed in the victim's browser, potentially resulting in session compromise.
The root cause lies in insufficient input validation and sanitization within the Web Dynpro Java component. The application accepts user-controlled input and incorporates it into content that is later served to other users without properly neutralizing potentially malicious code or references. The vulnerability is classified under CWE-94 (Improper Control of Generation of Code / Code Injection). The attack is initiated remotely over the network and requires no authentication, though user interaction is necessary for the injected content to execute in the victim's browser context.
Vulnerability details
SAP NetWeaver Application Server Java (Web Dynpro Java) contains a Code Injection vulnerability that allows an unauthenticated attacker to supply crafted input that is interpreted by the application and causes it to reference attacker-controlled content.
What an attacker can do
This vulnerability allows a remote, unauthenticated attacker to execute arbitrary client-side code in the browsers of users accessing the affected SAP NetWeaver functionality. As a result: Session Compromise: Attacker-controlled code runs in the victim's browser context, potentially capturing session tokens, credentials, or other sensitive data. Credential Harvesting: Injected scripts can capture keystrokes, form submissions, or authentication tokens entered by the victim during the session. Persistent Attack Surface: If stored XSS is achievable, each subsequent user accessing the affected Web Dynpro component becomes a victim without further attacker interaction.
Disclosure timeline
2026-01-29 Reported to Vendor
2026-02-23 CVE ID Reserved
2026-04-13 CVE Published
References
2026-06-17 (NVD record)
Credits
Chandru R – Payatu Security Consulting Pvt. Ltd.
















