Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Enterprise Portal |
|
| Vendors & Products |
Sap
Sap netweaver Enterprise Portal |
Tue, 09 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability. | |
| Title | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal | |
| Weaknesses | CWE-489 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-12-09T16:02:40.568Z
Reserved: 2025-04-16T13:25:17.023Z
Link: CVE-2025-42872
Updated: 2025-12-09T14:24:03.939Z
Status : Deferred
Published: 2025-12-09T16:17:51.107
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-42872
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:04:38Z