PT-2025-28288 · Sap · Sap Netweaver Application Server Abap+1
Published
2025-07-08
·
Updated
2025-07-24
·
CVE-2025-42969
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP NetWeaver Application Server ABAP and ABAP Platform (affected versions not specified)
Description:
The issue allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. When a victim clicks on this crafted URL, they unknowingly execute the malicious payload in their browser. On successful exploitation, the attacker can access or modify sensitive information within the scope of the victim's web browser, with no impact on the availability of the application.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abap Platform
Sap Netweaver Application Server Abap