CVE-2025-42945
Last modified
CVE-2025-42945 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its manipulation. There is no impact on availability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-42945?
How severe is CVE-2025-42945?
How do I fix CVE-2025-42945?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4294Improper Neutralization of Input During Web Page Generation …4.8
- CVE-2025-42940SAP CommonCryptoLib does not perform necessary boundary chec…7.5
- CVE-2025-42941SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vu…3.5
- CVE-2025-42942SAP NetWeaver Application Server for ABAP has cross-site scr…6.1
- CVE-2025-42943SAP GUI for Windows may allow the leak of NTML hashes when s…4.5
- CVE-2025-42944Due to a deserialization vulnerability in SAP NetWeaver, an …10
- CVE-2025-42946Due to directory traversal vulnerability in SAP S/4HANA (Ban…6.9
- CVE-2025-42947SAP FICA ODN framework allows a high privileged user to inje…5.5
- CVE-2025-42948Due to a Cross-Site Scripting (XSS) vulnerability in SAP Net…6.1
- CVE-2025-42949Due to a missing authorization check in the ABAP Platform, a…4.9
- CVE-2025-4295Improper Validation of Certificate with Host Mismatch vulner…4.6
- CVE-2025-42950SAP Landscape Transformation (SLT) allows an attacker with u…9.9
Are you affected by CVE-2025-42945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
