CVE-2026-44757

SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certain conditions, when accessed by a victim, the injected script could execute in the user�s browser within the context of the application. This issue has a low impact on the confidentiality and integrity of the application with no impact on availability.
Configurations

No configuration.

History

23 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) SAP Wily Introscope Enterprise Manager permite a un atacante no autenticado crear una URL especialmente diseñada. Bajo ciertas condiciones, cuando es accedido por una víctima, el script inyectado podría ejecutarse en el navegador del usuario dentro del contexto de la aplicación. Este problema tiene un bajo impacto en la confidencialidad e integridad de la aplicación, sin impacto en la disponibilidad.

09 Jun 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-09 01:16

Updated : 2026-07-23 08:10


NVD link : CVE-2026-44757

Mitre link : CVE-2026-44757

CVE.ORG link : CVE-2026-44757


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')