CVE-2025-42962: SAP SE SAP Business Warehouse Business Explorer Web 3.5 Loading Animation

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.

Affected products

  • SAP SE SAP Business Warehouse Business Explorer Web 3.5 Loading Animation: version 200 only; version 300 only; version 400 only; version 916 only; version 731 only; version 740 only; …

Published 2025-07-08. Last modified 2026-06-17.