Cross-Site Scripting Vulnerability in SAP NetWeaver ABAP Platform
CVE-2025-42938
What is CVE-2025-42938?
A Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform allows unauthenticated attackers to create and share malicious links. When an authenticated user accesses such a link, the injected malicious input is executed during page generation. This execution can lead to unauthorized access or manipulation of sensitive information within the victim's browsing session, posing significant risks to data confidentiality and integrity. Users are urged to apply available patches and enhance their security measures to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver ABAP Platform S4CRM 100
SAP NetWeaver ABAP Platform 200
SAP NetWeaver ABAP Platform 204
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved