Server-Side Scripting Vulnerability in SAP NetWeaver Application Server ABAP
CVE-2025-42969

6.1MEDIUM

What is CVE-2025-42969?

SAP NetWeaver Application Server ABAP and the ABAP Platform contain a vulnerability that allows unauthenticated attackers to inject malicious scripts through specially crafted URLs. When victims are tricked into clicking these links, they inadvertently execute the malicious payload within their browsers. This unauthorized access enables attackers to view or modify sensitive information in the user's web session while maintaining the availability of the application. Users of affected products should take immediate action to mitigate this risk.

Affected Version(s)

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 740

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 750

SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 751

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42969 : Server-Side Scripting Vulnerability in SAP NetWeaver Application Server ABAP