CVE-2025-42901: Code Injection vulnerability in SAP Application Server for ABAP (BAPI Browser)
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42901?
CVE-2025-42901 is classified with low severity as it impacts confidentiality and integrity in a limited manner.
How do I fix CVE-2025-42901?
To fix CVE-2025-42901, apply the latest SAP security patches and follow guidance from SAP notes regarding secure coding practices.
Who is affected by CVE-2025-42901?
Authenticated users of the SAP Application Server for ABAP who interact with the BAPI explorer functionality are potentially affected by CVE-2025-42901.
What exploitability exists for CVE-2025-42901?
CVE-2025-42901 can be exploited by an authenticated attacker to inject malicious JavaScript payloads that may affect other users.
What are the potential impacts of CVE-2025-42901?
The potential impacts of CVE-2025-42901 primarily involve the unauthorized execution of malicious scripts in a victim's browser.