Security Flaw in SAP NetWeaver Application Server ABAP Exposes Users to Threats
CVE-2025-42956

6.1MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 July 2025

What is CVE-2025-42956?

An issue exists in SAP NetWeaver Application Server ABAP and ABAP Platform that allows unauthenticated attackers to craft malicious links. If an authenticated user clicks such a link, it can manipulate the server into generating content based on the injected data. This execution within the user's browser may compromise confidentiality and integrity but does not affect the availability of the application, thereby posing a risk to user data and trust.

Affected Version(s)

SAP NetWeaver Application Server ABAP SAP_BASIS 700

SAP NetWeaver Application Server ABAP SAP_BASIS 701

SAP NetWeaver Application Server ABAP SAP_BASIS 702

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42956 : Security Flaw in SAP NetWeaver Application Server ABAP Exposes Users to Threats