CVE 6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform_CVE-2025-42948

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the websites page generation, resulting in the creation of malicious content. When this malicious content gets executed, the attacker could gain the ability to access/modify information within the scope of victims browser.

AI Analysis

Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform affecting multiple versions, allowing attackers to inject malicious scripts via crafted links.

Basic Information

ID CVE-2025-42948
Source sap
Published Aug 12, 2025 at 02:08

Affected Product

Vendor SAP_SE
Product SAP NetWeaver ABAP Platform
Version S4CRM 100
Affected Versions SAP_SE SAP NetWeaver ABAP Platform S4CRM 100
SAP_SE SAP NetWeaver ABAP Platform 200
SAP_SE SAP NetWeaver ABAP Platform 204
SAP_SE SAP NetWeaver ABAP Platform 205
SAP_SE SAP NetWeaver ABAP Platform 206
SAP_SE SAP NetWeaver ABAP Platform S4CEXT 107
SAP_SE SAP NetWeaver ABAP Platform 108
SAP_SE SAP NetWeaver ABAP Platform 109
SAP_SE SAP NetWeaver ABAP Platform BBPCRM 713
SAP_SE SAP NetWeaver ABAP Platform 714

CWE Classification

AI Assessment

AI Score 6.1 / 10
AI Severity MEDIUM
Vendor SAP
Product NetWeaver ABAP Platform
Version S4CRM 100, 200, 204, 205, 206, S4CEXT 107, 108, 109, BBPCRM 713, 714

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.