Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.
History

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap abap Platform
Sap netweaver Abap
Vendors & Products Sap
Sap abap Platform
Sap netweaver Abap

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 02:15:00 +0000

Type Values Removed Values Added
Description Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.
Title Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-09-09T02:11:33.755Z

Updated: 2025-09-09T13:26:55.759Z

Reserved: 2025-04-16T13:25:34.582Z

Link: CVE-2025-42938

cve-icon Vulnrichment

Updated: 2025-09-09T13:26:48.689Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T02:15:41.977

Modified: 2025-09-09T16:28:43.660

Link: CVE-2025-42938

cve-icon Redhat

No data.