SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could access and modify limited information within the scope of victim's browser. This vulnerability has no impact on availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 12 Aug 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap netweaver Application Server For Abap |
|
Vendors & Products |
Sap
Sap netweaver Application Server For Abap |
Tue, 12 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could access and modify limited information within the scope of victim's browser. This vulnerability has no impact on availability of the application. | |
Title | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-08-12T02:05:34.992Z
Updated: 2025-08-12T14:02:26.379Z
Reserved: 2025-04-16T13:25:37.187Z
Link: CVE-2025-42942

Updated: 2025-08-12T14:02:23.183Z

Status : Awaiting Analysis
Published: 2025-08-12T03:15:26.810
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-42942

No data.