Cross-Site Scripting Vulnerability in SAP NetWeaver by SAP
CVE-2025-31325
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-31325?
A Cross-Site Scripting vulnerability has been identified in SAP NetWeaver, specifically within the ABAP Keyword Documentation. This vulnerability allows unauthenticated attackers to inject malicious JavaScript code into a webpage via an unprotected parameter. When unsuspecting users visit the compromised page, the injected script executes within their browser, potentially giving attackers limited access to sensitive information. Importantly, this vulnerability does not compromise data integrity or availability, as it operates solely within the client’s browser context.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver (ABAP Keyword Documentation) SAP_BASIS 758
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved