CVE-2025-42945

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
12/08/2025
Last modified:
12/08/2025

Description

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its manipulation. There is no impact on availability.