Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on the confidentiality and integrity of the application with no impact on availability.

Project Subscriptions

Vendors Products
Sap Business One (job Service) Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 10 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Business One (job Service)
Vendors & Products Sap Se
Sap Se sap Business One (job Service)

Tue, 10 Mar 2026 00:45:00 +0000

Type Values Removed Values Added
Description Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on the confidentiality and integrity of the application with no impact on availability.
Title DOM-based Cross-Site Scripting (XSS) Vulnerability in SAP Business One (Job Service)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2026-03-10T16:53:45.896Z

Reserved: 2025-12-09T22:06:32.759Z

Link: CVE-2026-0489

cve-icon Vulnrichment

Updated: 2026-03-10T15:36:16.863Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-10T17:31:05.073

Modified: 2026-03-11T13:53:47.157

Link: CVE-2026-0489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-10T14:06:20Z

Weaknesses