CVE-2025-42956 Details
Description
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used by the web site page generation to create content which when executed in the victim's browser leading to low impact on Confidentiality and Integrity with no effect on Availability of the application.
A cross-site scripting vulnerability has been identified in SAP NetWeaver Application Server ABAP and ABAP Platform. This issue allows an unauthenticated attacker to create a malicious link that, when clicked by an authenticated user, injects data into the website's page generation process. The injected content is then executed in the victim's browser, leading to a low impact on confidentiality and integrity, with no effect on the application's availability.
Users are advised to review and implement the latest SAP Security Notes. Security fixes for SAP NetWeaver based products are delivered with the support packages. For information on the latest SAP Security Patch Day Notes, refer to the SAP Security Patch Day Bulletin Archive.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3617131 | [email protected] | Permissions Required |
| https://url.sap/sapsecuritypatchday | [email protected] | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sap sap basis | 700 701 702 731 740 750 751 752 753 754 755 756 757 758 816 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | Initial Analysis | [email protected] |
| Jul 8, 2025 | New CVE Received | [email protected] |