PT-2025-36561 · Sap · Sap Netweaver/Abap Platform

Published

2025-09-09

·

Updated

2025-09-09

·

CVE-2025-42938

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver ABAP Platform (affected versions not specified)
Description: The SAP NetWeaver ABAP Platform is susceptible to a Cross-Site Scripting (XSS) issue. An unauthenticated attacker can create a malicious link and, upon a user clicking it, inject malicious content that can be executed within the victim’s browser. This can lead to unauthorized access or modification of information within the user's browser scope, compromising confidentiality and integrity.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-42938

Affected Products

Sap Netweaver/Abap Platform