SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application. | |
Title | Code Injection vulnerability in SAP Application Server for ABAP (BAPI Browser) | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-10-14T00:17:23.355Z
Reserved: 2025-04-16T13:25:25.736Z
Link: CVE-2025-42901

No data.

Status : Received
Published: 2025-10-14T01:15:31.733
Modified: 2025-10-14T01:15:31.733
Link: CVE-2025-42901

No data.

No data.