Server-Side Scripting Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2025-42969
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 July 2025
What is CVE-2025-42969?
SAP NetWeaver Application Server ABAP and the ABAP Platform contain a vulnerability that allows unauthenticated attackers to inject malicious scripts through specially crafted URLs. When victims are tricked into clicking these links, they inadvertently execute the malicious payload within their browsers. This unauthorized access enables attackers to view or modify sensitive information in the user's web session while maintaining the availability of the application. Users of affected products should take immediate action to mitigate this risk.
Affected Version(s)
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 740
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 750
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 751