CVE-2025-42945 Information

Description

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit this vulnerability could lead to limited access to data or its manipulation. There is no impact on availability.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://me.sap.com/notes/3585491 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

CNNVD-202508-981 (Published: 2025-08-12)

Share on: