Cross-Site Scripting Vulnerability in SAP NetWeaver by SAP
CVE-2025-31325
5.8MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-31325?
A Cross-Site Scripting vulnerability has been identified in SAP NetWeaver, specifically within the ABAP Keyword Documentation. This vulnerability allows unauthenticated attackers to inject malicious JavaScript code into a webpage via an unprotected parameter. When unsuspecting users visit the compromised page, the injected script executes within their browser, potentially giving attackers limited access to sensitive information. Importantly, this vulnerability does not compromise data integrity or availability, as it operates solely within the client’s browser context.
Affected Version(s)
SAP NetWeaver (ABAP Keyword Documentation) SAP_BASIS 758