Cross-Site Scripting Vulnerability in SAP NetWeaver by SAP
CVE-2025-31325

5.8MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 June 2025

What is CVE-2025-31325?

A Cross-Site Scripting vulnerability has been identified in SAP NetWeaver, specifically within the ABAP Keyword Documentation. This vulnerability allows unauthenticated attackers to inject malicious JavaScript code into a webpage via an unprotected parameter. When unsuspecting users visit the compromised page, the injected script executes within their browser, potentially giving attackers limited access to sensitive information. Importantly, this vulnerability does not compromise data integrity or availability, as it operates solely within the client’s browser context.

Affected Version(s)

SAP NetWeaver (ABAP Keyword Documentation) SAP_BASIS 758

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-31325 : Cross-Site Scripting Vulnerability in SAP NetWeaver by SAP