CNNVD-202510-2084 Information

CNNVD ID

CNNVD-202510-2084

CVE-2025-42901

  • CNNVD Published: 2025-10-14

Description (Chinese)

SAP Application Server for ABAP是德国思爱普(SAP)公司的一个负载均衡、内存管理平台。 SAP Application Server for ABAP存在代码注入漏洞,该漏洞源于允许经过身份验证的攻击者存储恶意JavaScript有效载荷,可能导致跨站脚本攻击。

Description (English)

SAP Application Server for ABAP is a load-balanced, memory management platform for SAP Germany. SAP Application Server for AMAP has a code-infusion loophole, which stems from allowing the identity-identified assailant to store the malicious JavaScript payload, which may result in a cross-site script attack.

Hazard Level

High

Vulnerability Type

代码注入

Affected Vendor

思爱普

Published

2025-10-14

Last Modified

2026-02-24

References

https://me.sap.com/notes/3652788 https://url.sap/sapsecuritypatchday https://access.redhat.com/security/cve/cve-2025-42901

Patch

https://www.sap.com/index.html

Share on: