CVE-2025-42956
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-08

Last updated on: 2025-10-27

Assigner: SAP SE

Description
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, injected input data will be used by the web site page generation to create content which when executed in the victim's browser leading to low impact on Confidentiality and Integrity with no effect on Availability of the application.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-08
Last Modified
2025-10-27
Generated
2026-05-07
AI Q&A
2025-07-08
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 15 associated CPEs
Vendor Product Version / Range
sap sap_basis 700
sap sap_basis 701
sap sap_basis 702
sap sap_basis 731
sap sap_basis 740
sap sap_basis 750
sap sap_basis 751
sap sap_basis 752
sap sap_basis 753
sap sap_basis 754
sap sap_basis 755
sap sap_basis 756
sap sap_basis 757
sap sap_basis 758
sap sap_basis 816
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link. When an authenticated user clicks this link, the injected input data is used by the website to generate content that executes in the user's browser, potentially leading to low impact on confidentiality and integrity.


How can this vulnerability impact me? :

If an authenticated user clicks the malicious link, the attacker can cause injected content to execute in the user's browser, which may lead to limited disclosure or alteration of information (low impact on confidentiality and integrity). There is no impact on the availability of the application.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart