CVE-2025-42901

SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.
Configurations

No configuration.

History

14 Oct 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 01:15

Updated : 2025-10-14 19:36


NVD link : CVE-2025-42901

Mitre link : CVE-2025-42901

CVE.ORG link : CVE-2025-42901


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')