CVE-2025-42886
Last modified
CVE-2025-42886 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser context. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser context. This could allow the attacker to access or modify information within the victim�s browser scope, impacting confidentiality and integrity, while availability remains unaffected
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Connector | 4.8 |
References
- https://me.sap.com/notes/3665907Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-42886?
How severe is CVE-2025-42886?
How do I fix CVE-2025-42886?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4288A vulnerability classified as critical has been found in PCM…9.8
- CVE-2025-42880Due to missing input sanitation, SAP Solution Manager allows…9.9
- CVE-2025-42882Due to a missing authorization check in SAP NetWeaver Applic…4.3
- CVE-2025-42883Migration Workbench (DX Workbench) in SAP NetWeaver Applicat…2.7
- CVE-2025-42884SAP NetWeaver Enterprise Portal allows an unauthenticated at…6.5
- CVE-2025-42885Due to missing authentication, SAP HANA 2.0 (hdbrss) allows …5.8
- CVE-2025-42887Due to missing input sanitation, SAP Solution Manager allows…9.9
- CVE-2025-42888SAP GUI for Windows may allow a highly privileged user on th…5.5
- CVE-2025-42889SAP Starter Solution allows an authenticated attacker to exe…5.4
- CVE-2025-4289A vulnerability classified as critical was found in PCMan FT…9.8
- CVE-2025-42890SQL Anywhere Monitor (Non-GUI) baked credentials into the co…10
- CVE-2025-42891Due to a missing authorization check in SAP Enterprise Searc…5.5
Are you affected by CVE-2025-42886?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
