Security Advisory
CVE-2025-42872
6.1
MEDIUM
Vulnerability Description
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.
Published Date
December 9, 2025
Official Source
NIST NVD Advisory