PT-2025-32608 · Sap · Sap Netweaver/Abap Platform

Published

2025-08-11

·

Updated

2025-08-12

·

CVE-2025-42948

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver ABAP Platform (affected versions not specified)
Description: A Cross-Site Scripting (XSS) issue exists in SAP NetWeaver ABAP Platform. An unauthenticated attacker can create a malicious link and distribute it publicly. If an authenticated user clicks on this link, injected input is processed during web page generation, resulting in malicious content execution. This allows the attacker to potentially access or modify information within the victim’s browser.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-16304
CVE-2025-42948

Affected Products

Sap Netweaver/Abap Platform