CVE-2025-42920 Details
Description
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim clicks on the link, the injected input is processed during the page generation, resulting in the execution of malicious content. This execution allows the attacker to access and modify information within the victim's browser scope, impacting confidentiality and integrity, while availability remains unaffected.
A Cross-Site Scripting (XSS) vulnerability has been identified in SAP Supplier Relationship Management. This issue allows an unauthenticated attacker to create a malicious link that, when clicked by an authenticated user, executes harmful content. The vulnerability arises because the injected input is processed during page generation, enabling the attacker to access and modify information within the victim's browser. This impacts the confidentiality and integrity of the user's data, while availability remains unaffected.
Users are advised to review and implement the SAP Security Note related to this vulnerability. This can be done through the SAP Security Patch Day, which occurs on the second Tuesday of each month. For more information, consult the SAP Security Notes FAQ or access SAP Security Notes through the SAP for Me platform.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3647098 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap supplier relationship management | 7.0 - |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Initial Analysis | [email protected] |
| Sep 9, 2025 | New CVE Received | [email protected] |