CVE-2025-42886: Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector
Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed during web page generation, resulting in the execution of malicious content in the victim's browser context. This could allow the attacker to access or modify information within the victim�s browser scope, impacting confidentiality and integrity, while availability remains unaffected
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42886?
CVE-2025-42886 is considered a high severity vulnerability due to its potential for unauthorized access via reflected cross-site scripting.
How do I fix CVE-2025-42886?
To mitigate CVE-2025-42886, ensure that you apply the latest security patches from SAP for the Business Connector software.
What does CVE-2025-42886 allow an attacker to do?
CVE-2025-42886 allows an unauthenticated attacker to craft a malicious link that, when accessed by an authenticated user, can execute injected scripts.
Is CVE-2025-42886 exploitable without user interaction?
No, CVE-2025-42886 requires user interaction since the victim must click on the malicious link for exploitation to occur.
What software is affected by CVE-2025-42886?
CVE-2025-42886 affects SAP Business Connector, making it vulnerable to reflected cross-site scripting attacks.