Security Flaw in SAP NetWeaver Application Server ABAP Exposes Users to Threats
CVE-2025-42956
6.1MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 July 2025
What is CVE-2025-42956?
An issue exists in SAP NetWeaver Application Server ABAP and ABAP Platform that allows unauthenticated attackers to craft malicious links. If an authenticated user clicks such a link, it can manipulate the server into generating content based on the injected data. This execution within the user's browser may compromise confidentiality and integrity but does not affect the availability of the application, thereby posing a risk to user data and trust.
Affected Version(s)
SAP NetWeaver Application Server ABAP SAP_BASIS 700
SAP NetWeaver Application Server ABAP SAP_BASIS 701
SAP NetWeaver Application Server ABAP SAP_BASIS 702