CVE-2025-42886 - CVE House
Back to Database
Status published Medium CVE-2025-42886

Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector

Vulnerability Description

Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser context. This could allow the attacker to access or modify information within the victim�s browser scope, impacting confidentiality and integrity, while availability remains unaffected

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-42886

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SAP Business Connector
Vulnerable Versions:
SAP BC 4.8

Timeline

Official Publish: November 11th, 2025
Last Modified: November 12th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)