Vulnerability Description
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-42901?
CVE-2025-42901 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BA...
How severe is CVE-2025-42901?
CVE-2025-42901 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-42901?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.