SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap application Server Sap netweaver Application Server For Abap Sap sap Web Application Server |
|
| Vendors & Products |
Sap
Sap application Server Sap netweaver Application Server For Abap Sap sap Web Application Server |
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application. | |
| Title | Code Injection vulnerability in SAP Application Server for ABAP (BAPI Browser) | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-10-14T00:17:23.355Z
Updated: 2025-10-14T15:21:26.115Z
Reserved: 2025-04-16T13:25:25.736Z
Link: CVE-2025-42901
Updated: 2025-10-14T15:21:20.258Z
Status : Awaiting Analysis
Published: 2025-10-14T01:15:31.733
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-42901
No data.