Security Flaw in SAP Application Server for ABAP
CVE-2025-42901

5.4MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
14 October 2025

What is CVE-2025-42901?

An issue within the SAP Application Server for ABAP allows authenticated users to inject malicious JavaScript into the BAPI explorer functionality. When other users access this functionality, the injected scripts may execute in their browsers, potentially compromising user interactions without affecting the application's overall availability or core data integrity.

Affected Version(s)

SAP Application Server for ABAP (BAPI Browser) SAP_BASIS 700

SAP Application Server for ABAP (BAPI Browser) SAP_BASIS 701

SAP Application Server for ABAP (BAPI Browser) SAP_BASIS 702

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.