CVE-2025-42948: SAP SE SAP NetWeaver Abap Platform

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When this malicious content gets executed, the attacker could gain the ability to access/modify information within the scope of victim�s browser.

Affected products

  • SAP SE SAP NetWeaver Abap Platform: version S4CRM 100 only; version 200 only; version 204 only; version 205 only; version 206 only; version S4CEXT 107 only; …

Published 2025-08-12. Last modified 2026-06-17.