Vulnerability Description
Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are not impacted.
CVSS Score
LOW
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-42990?
CVE-2025-42990 is a vulnerability with a CVSS score of 3.0 (LOW). Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue coul...
How severe is CVE-2025-42990?
CVE-2025-42990 has been rated LOW with a CVSS base score of 3.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-42990?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.