Security Flaw in SAP NetWeaver Application Server ABAP Exposes Users to Threats
CVE-2025-42956
6.1MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 July 2025
What is CVE-2025-42956?
An issue exists in SAP NetWeaver Application Server ABAP and ABAP Platform that allows unauthenticated attackers to craft malicious links. If an authenticated user clicks such a link, it can manipulate the server into generating content based on the injected data. This execution within the user's browser may compromise confidentiality and integrity but does not affect the availability of the application, thereby posing a risk to user data and trust.
Affected Version(s)
SAP NetWeaver Application Server ABAP SAP_BASIS 700
SAP NetWeaver Application Server ABAP SAP_BASIS 701
SAP NetWeaver Application Server ABAP SAP_BASIS 702
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved