Security Advisory

CVE-2025-42872

6.1
MEDIUM

Vulnerability Description

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.
Published Date December 9, 2025
Official Source NIST NVD Advisory