CVE-2025-42990: SAP SE SAPUI5 Applications

Low severity, CVSS 3.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are not impacted.

Affected products

  • SAP SE SAPUI5 Applications: version 754 only; version 755 only; version 756 only; version 757 only; version 758 only

Published 2025-06-10. Last modified 2026-06-17.