CVE-2025-42872
BaseFortify
Publication date: 2025-12-09
Last updated on: 2025-12-09
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | netweaver_enterprise_portal | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-489 | The product is released with debugging code still enabled or active. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Cross-Site Scripting (XSS) issue in SAP NetWeaver Enterprise Portal. It allows an unauthenticated attacker to inject malicious scripts that run in other users' browsers. These scripts can steal session cookies, tokens, and other sensitive information from those users.
How can this vulnerability impact me? :
The vulnerability can lead to theft of session cookies, tokens, and sensitive information from users, potentially allowing attackers to impersonate users or access their accounts. However, it has a low impact on confidentiality and integrity and no impact on availability.