Cross-Site Scripting Vulnerability in SAP NetWeaver ABAP Platform
CVE-2025-42938
6.1MEDIUM
What is CVE-2025-42938?
A Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform allows unauthenticated attackers to create and share malicious links. When an authenticated user accesses such a link, the injected malicious input is executed during page generation. This execution can lead to unauthorized access or manipulation of sensitive information within the victim's browsing session, posing significant risks to data confidentiality and integrity. Users are urged to apply available patches and enhance their security measures to mitigate this risk.
Affected Version(s)
SAP NetWeaver ABAP Platform S4CRM 100
SAP NetWeaver ABAP Platform 200
SAP NetWeaver ABAP Platform 204