Cross-site scripting (XSS) vulnerability in the Integration Repository in the SAP Exchange Infrastructure (BC-XI) component in SAP NetWeaver allows remote attackers to inject arbitrary web script or HTML via vectors related to the ESR application and a DIR error.
https://service.sap.com/sap/support/notes/1788080
https://exchange.xforce.ibmcloud.com/vulnerabilities/91095
https://erpscan.io/advisories/erpscan-14-005-sap-netweaver-dir-error-xss/