PT-2025-28281 · Sap · Sap Business Warehouse
Published
2025-07-08
·
Updated
2025-07-23
·
CVE-2025-42962
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP Business Warehouse (Business Explorer Web) (affected versions not specified)
Description:
The issue allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of the victim's browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Business Warehouse