6.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.
Basic Information
ID
CVE-2025-42938
Source
sap
Published
Sep 9, 2025 at 02:11
Affected Product
Vendor
SAP_SE
Product
SAP NetWeaver ABAP Platform
Version
S4CRM 100
Affected Versions
SAP_SE SAP NetWeaver ABAP Platform S4CRM 100
SAP_SE SAP NetWeaver ABAP Platform 200
SAP_SE SAP NetWeaver ABAP Platform 204
SAP_SE SAP NetWeaver ABAP Platform 205
SAP_SE SAP NetWeaver ABAP Platform 206
SAP_SE SAP NetWeaver ABAP Platform S4CEXT 109
SAP_SE SAP NetWeaver ABAP Platform BBPCRM 713
SAP_SE SAP NetWeaver ABAP Platform 714
SAP_SE SAP NetWeaver ABAP Platform 200
SAP_SE SAP NetWeaver ABAP Platform 204
SAP_SE SAP NetWeaver ABAP Platform 205
SAP_SE SAP NetWeaver ABAP Platform 206
SAP_SE SAP NetWeaver ABAP Platform S4CEXT 109
SAP_SE SAP NetWeaver ABAP Platform BBPCRM 713
SAP_SE SAP NetWeaver ABAP Platform 714