Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24208 | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When this malicious content gets executed, the attacker could gain the ability to access/modify information within the scope of victim�s browser. |
Thu, 14 Aug 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap abap Platform Sap netweaver Sap netweaver Abap Sap sap Netweaver |
|
| Vendors & Products |
Sap
Sap abap Platform Sap netweaver Sap netweaver Abap Sap sap Netweaver |
Tue, 12 Aug 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the creation of malicious content. When this malicious content gets executed, the attacker could gain the ability to access/modify information within the scope of victim�s browser. | |
| Title | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-08-13T20:20:27.593Z
Reserved: 2025-04-16T13:25:37.188Z
Link: CVE-2025-42948
Updated: 2025-08-12T13:30:51.530Z
Status : Deferred
Published: 2025-08-12T03:15:27.493
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-42948
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:46:52Z
EUVD