Cross-Site Scripting Vulnerability in SAP NetWeaver ABAP Platform
CVE-2025-42938

6.1MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 September 2025

What is CVE-2025-42938?

A Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform allows unauthenticated attackers to create and share malicious links. When an authenticated user accesses such a link, the injected malicious input is executed during page generation. This execution can lead to unauthorized access or manipulation of sensitive information within the victim's browsing session, posing significant risks to data confidentiality and integrity. Users are urged to apply available patches and enhance their security measures to mitigate this risk.

Affected Version(s)

SAP NetWeaver ABAP Platform S4CRM 100

SAP NetWeaver ABAP Platform 200

SAP NetWeaver ABAP Platform 204

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42938 : Cross-Site Scripting Vulnerability in SAP NetWeaver ABAP Platform