4.9

CVSS3.1

CVE-2025-42949 - Missing Authorization check in ABAP Platform

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper auโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:08 a.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 8:20 p.m.

6.1

CVSS3.1

CVE-2025-42948 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website๏ฟฝs page generation, resultinโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:08 a.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 8:20 p.m.

6.9

CVSS3.1

CVE-2025-42946 - Directory Traversal vulnerability in SAP S/4HANA (Bank Communication Management)

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attackeโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:07 a.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 8:20 p.m.

6.1

CVSS3.1

CVE-2025-42945 - HTML Injection vulnerability in SAP NetWeaver Application Server ABAP

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its โ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 3:56 p.m.

4.5

CVSS3.1

CVE-2025-42943 - Information Disclosure in SAP GUI for Windows

SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP Gโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 3:57 p.m.

6.1

CVSS3.1

CVE-2025-42942 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP

SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could acceโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 2:25 p.m.

3.5

CVSS3.1

CVE-2025-42941 - Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)

SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. While administrative access is neceโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 2:25 p.m.

5.4

CVSS3.1

CVE-2025-42936 - Missing Authorization check in SAP NetWeaver Application Server for ABAP

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact โ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 13, 2025, 3:03 p.m.

4.1

CVSS3.1

CVE-2025-42935 - Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communโ€ฆ

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the aโ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:05 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 2:25 p.m.

4.3

CVSS3.1

CVE-2025-42934 - CRLF Injection vulnerability in SAP S/4HANA (Supplier invoice)

SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted Sites' configuration by injecting line feed (LF) characters into application inputs. This vulnerability has a low impact on the โ€ฆ

๐Ÿ“… Published: Aug. 12, 2025, 2:04 a.m. ๐Ÿ”„ Last Modified: Aug. 12, 2025, 2:25 p.m.
Total resulsts: 305855
Page 100 of 30,586
ยซ previous page ยป next page
Filters