CVE 6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform_CVE-2025-42938

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.

Basic Information

ID CVE-2025-42938
Source sap
Published Sep 9, 2025 at 02:11

Affected Product

Vendor SAP_SE
Product SAP NetWeaver ABAP Platform
Version S4CRM 100
Affected Versions SAP_SE SAP NetWeaver ABAP Platform S4CRM 100
SAP_SE SAP NetWeaver ABAP Platform 200
SAP_SE SAP NetWeaver ABAP Platform 204
SAP_SE SAP NetWeaver ABAP Platform 205
SAP_SE SAP NetWeaver ABAP Platform 206
SAP_SE SAP NetWeaver ABAP Platform S4CEXT 109
SAP_SE SAP NetWeaver ABAP Platform BBPCRM 713
SAP_SE SAP NetWeaver ABAP Platform 714

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.