Security Flaw in SAP Application Server for ABAP
CVE-2025-42901
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-42901?
An issue within the SAP Application Server for ABAP allows authenticated users to inject malicious JavaScript into the BAPI explorer functionality. When other users access this functionality, the injected scripts may execute in their browsers, potentially compromising user interactions without affecting the application's overall availability or core data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Application Server for ABAP (BAPI Browser) SAP_BASIS 700
SAP Application Server for ABAP (BAPI Browser) SAP_BASIS 701
SAP Application Server for ABAP (BAPI Browser) SAP_BASIS 702
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved