CVE-2025-42938 - CVE House
Back to Database
Status published Medium CVE-2025-42938

Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform

Vulnerability Description

Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When executed, this content allows the attacker to access or modify information within the victim's browser scope, impacting the confidentiality and integrity�while availability remains unaffected.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-42938

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SAP NetWeaver ABAP Platform
Vulnerable Versions:
S4CRM 100, 200, 204, 205, 206, S4CEXT 109, BBPCRM 713, 714

Timeline

Official Publish: September 9th, 2025
Last Modified: September 9th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)