CVE-2025-42975: SAP SE SAP NetWeaver Application Server Abap Bic Document

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP NetWeaver Application Server ABAP (BIC Document) allows an unauthenticated attacker to craft a URL link which, when accessed on the BIC Document application, embeds a malicious script. When a victim clicks on this link, the script executes in the victim's browser, allowing the attacker to access and/or modify information related to the web client without affecting availability.

Affected products

  • SAP SE SAP NetWeaver Application Server Abap Bic Document: version S4COREOP 104 only; version 105 only; version 106 only; version 107 only; version 108 only; version 602 only; …

Published 2025-08-12. Last modified 2026-06-17.