6.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the websites page generation, resulting in the creation of malicious content. When this malicious content gets executed, the attacker could gain the ability to access/modify information within the scope of victims browser.
AI Analysis
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform affecting multiple versions, allowing attackers to inject malicious scripts via crafted links.
Basic Information
ID
CVE-2025-42948
Source
sap
Published
Aug 12, 2025 at 02:08
Affected Product
Vendor
SAP_SE
Product
SAP NetWeaver ABAP Platform
Version
S4CRM 100
Affected Versions
SAP_SE SAP NetWeaver ABAP Platform S4CRM 100
SAP_SE SAP NetWeaver ABAP Platform 200
SAP_SE SAP NetWeaver ABAP Platform 204
SAP_SE SAP NetWeaver ABAP Platform 205
SAP_SE SAP NetWeaver ABAP Platform 206
SAP_SE SAP NetWeaver ABAP Platform S4CEXT 107
SAP_SE SAP NetWeaver ABAP Platform 108
SAP_SE SAP NetWeaver ABAP Platform 109
SAP_SE SAP NetWeaver ABAP Platform BBPCRM 713
SAP_SE SAP NetWeaver ABAP Platform 714
SAP_SE SAP NetWeaver ABAP Platform 200
SAP_SE SAP NetWeaver ABAP Platform 204
SAP_SE SAP NetWeaver ABAP Platform 205
SAP_SE SAP NetWeaver ABAP Platform 206
SAP_SE SAP NetWeaver ABAP Platform S4CEXT 107
SAP_SE SAP NetWeaver ABAP Platform 108
SAP_SE SAP NetWeaver ABAP Platform 109
SAP_SE SAP NetWeaver ABAP Platform BBPCRM 713
SAP_SE SAP NetWeaver ABAP Platform 714
CWE Classification
AI Assessment
AI Score
6.1 / 10
AI Severity
MEDIUM
Vendor
SAP
Product
NetWeaver ABAP Platform
Version
S4CRM 100, 200, 204, 205, 206, S4CEXT 107, 108, 109, BBPCRM 713, 714