Code Injection Vulnerability in SAP NetWeaver Application Server Java
CVE-2026-27674

6.1MEDIUM

What is CVE-2026-27674?

A code injection vulnerability exists in SAP NetWeaver Application Server Java (Web Dynpro Java) that allows unauthenticated attackers to inject malicious input. This crafted input is processed by the application, causing it to execute attacker-controlled content when accessed by a victim. Such exploitation can lead to the execution of arbitrary client-side code, severely compromising the confidentiality and integrity of affected applications.

Affected Version(s)

SAP NetWeaver Application Server Java (Web Dynpro Java) WD-RUNTIME 7.50

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.