Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.
History

Tue, 09 Sep 2025 02:15:00 +0000

Type Values Removed Values Added
Description Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.
Title Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-09-09T02:11:33.755Z

Reserved: 2025-04-16T13:25:34.582Z

Link: CVE-2025-42938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-09T02:15:41.977

Modified: 2025-09-09T02:15:41.977

Link: CVE-2025-42938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.