CVE Feed

    Dashboard / CVE / CVE-2025-42938

    CVE-2025-42938

    Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.

    Published:Sep 9, 2025
    Last Modified:Apr 15, 2026
    EPS:Sep 9, 2025
    EPSS Score:0.00109
    CVSS Score:6.1

    Affected Products

    Vendor
    Sap
    Product
    Abap Platform
    Vendor
    Sap
    Product
    Netweaver Abap

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High