Reflected Cross-Site Scripting Vulnerability in SAP Business Connector
CVE-2025-42886
6.1MEDIUM
What is CVE-2025-42886?
A vulnerability in SAP Business Connector allows an unauthenticated attacker to craft a malicious link that, when accessed by an authenticated user, results in the execution of harmful scripts within the victim's browser. This reflected XSS flaw could compromise the confidentiality and integrity of user data as the injected content could be executed in the context of the user's session, posing significant security risks.
Affected Version(s)
SAP Business Connector SAP BC 4.8