cbcvebase.
CVE-2025-25242
published 2025-03-11

CVE-2025-25242: SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS)…

PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.24%
15.4th percentile
SAP NetWeaver Application Server ABAP allows malicious scripts to be executed in the application, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This has no impact on the availability of the application, but it can have some minor impact on its confidentiality and integrity.

Affected

12 ranges
VendorProductVersion rangeFixed in
gogs.iogogs>= 0 < 0.14.10.14.1
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.