CVE-2025-42948 Information

Description

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link the injected input is processed during the website?s page generation resulting in the creation of malicious content. When this malicious content gets executed the attacker could gain the ability to access/modify information within the scope of victim?s browser.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://me.sap.com/notes/3629871 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

CNNVD-202508-985 (Published: 2025-08-12)

Share on: