AP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on this crafted URL unknowingly executes the malicious payload in their browser. On successful exploitation, the attacker can access or modify sensitive information within the scope of victim's web browser, with no impact on availability of the application.
No configuration.
08 Jul 2025, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
08 Jul 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-07-08 01:15
Updated : 2025-07-08 16:18
NVD link : CVE-2025-42969
Mitre link : CVE-2025-42969
CVE.ORG link : CVE-2025-42969
JSON object : View
No product.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')