CVE-2025-42938
- EPSS 0.13%
- Veröffentlicht 09.09.2025 02:15:41
- Zuletzt bearbeitet 09.09.2025 16:28:43
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is pro...
CVE-2025-42925
- EPSS 0.04%
- Veröffentlicht 09.09.2025 02:15:40
- Zuletzt bearbeitet 09.09.2025 16:28:43
Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of severa...
CVE-2025-42922
- EPSS 0.07%
- Veröffentlicht 09.09.2025 02:15:40
- Zuletzt bearbeitet 09.09.2025 16:28:43
SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availabilit...
CVE-2025-42918
- EPSS 0.04%
- Veröffentlicht 09.09.2025 02:15:40
- Zuletzt bearbeitet 23.10.2025 12:44:38
SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availab...
CVE-2025-42911
- EPSS 0.04%
- Veröffentlicht 09.09.2025 02:15:38
- Zuletzt bearbeitet 23.10.2025 12:45:48
SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no eff...
CVE-2025-42948
- EPSS 0.21%
- Veröffentlicht 12.08.2025 02:08:17
- Zuletzt bearbeitet 12.08.2025 14:25:33
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is process...
CVE-2025-42945
- EPSS 0.05%
- Veröffentlicht 12.08.2025 02:05:51
- Zuletzt bearbeitet 12.08.2025 14:25:33
SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerabi...
CVE-2025-42942
- EPSS 0.21%
- Veröffentlicht 12.08.2025 02:05:34
- Zuletzt bearbeitet 12.08.2025 14:25:33
SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon...
CVE-2025-42936
- EPSS 0.05%
- Veröffentlicht 12.08.2025 02:05:19
- Zuletzt bearbeitet 23.10.2025 12:41:58
The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to pr...
CVE-2025-42935
- EPSS 0.02%
- Veröffentlicht 12.08.2025 02:05:09
- Zuletzt bearbeitet 12.08.2025 14:25:33
The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This lea...