CNNVD-202507-872 Information

CNNVD ID

CNNVD-202507-872

CVE-2025-42956

  • CNNVD Published: 2025-07-08

Description (Chinese)

SAP NetWeaver Application Server ABAP and ABAP Platform是德国思爱普(SAP)公司的一个运行和开发基于ABAP语言的应用程序的平台。 SAP NetWeaver Application Server ABAP and ABAP Platform 存在跨站脚本漏洞,该漏洞源于未验证攻击者可创建恶意链接,当已验证受害者点击时可能导致浏览器执行注入内容。

Description (English)

SAP NetWeaver Application Server ABAP and AMAP Platform is a platform for the operation and development of ABP-based applications. SAP NetWeaver Application Server ABAP and ABAAP Platform has a cross-site script loophole, which stems from the fact that unverified assailants can create malicious links that may lead to browsers performing input when victims have been identified.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

思爱普

Published

2025-07-08

Last Modified

2026-02-24

References

https://me.sap.com/notes/3617131 https://url.sap/sapsecuritypatchday

Patch

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/july-2025.html

Share on: