CVE-2025-31325Cross-site Scripting in SE SAP Netweaver

Severity
5.8MEDIUMNVD
EPSS
0.4%
top 41.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10

Description

Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the script executes in their browser, providing the attacker limited access to restricted information. The vulnerability does not affect data integrity or availability and operates entirely within the context of the client's browser.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

CVEListV5sap_se/sap_netweaverSAP_BASIS 758

🔴Vulnerability Details

2
CVEList
Cross-Site Scripting (XSS) Vulnerability in SAP NetWeaver (ABAP Keyword Documentation)2025-06-10
GHSA
GHSA-mf43-m2mh-xcq6: Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScri2025-06-10
CVE-2025-31325 — Cross-site Scripting | cvebase