6.1

CVSS3.1

CVE-2025-42948 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resultin…

📅 Published: Aug. 12, 2025, 2:08 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS3.1

CVE-2025-42946 - Directory Traversal vulnerability in SAP S/4HANA (Bank Communication Management)

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attacke…

📅 Published: Aug. 12, 2025, 2:07 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-42945 - HTML Injection vulnerability in SAP NetWeaver Application Server ABAP

SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerability could lead to limited access to data or its …

📅 Published: Aug. 12, 2025, 2:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS3.1

CVE-2025-42943 - Information Disclosure in SAP GUI for Windows

SAP GUI for Windows may allow the leak of NTML hashes when specific ABAP frontend services are called with UNC paths. For a successful attack, the attacker needs developer authorization in a specific Application Server ABAP to make changes in the code, and the victim needs to execute by using SAP G…

📅 Published: Aug. 12, 2025, 2:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-42942 - Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server for ABAP

SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon successful exploitation, the attacker could acce…

📅 Published: Aug. 12, 2025, 2:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-42941 - Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)

SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vulnerability due to inadequate external navigation protections for its link (<a>) elements. An attacker with administrative user privileges could exploit this by leveraging compromised or malicious pages. While administrative access is nece…

📅 Published: Aug. 12, 2025, 2:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-42936 - Missing Authorization check in SAP NetWeaver Application Server for ABAP

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact …

📅 Published: Aug. 12, 2025, 2:05 a.m. 🔄 Last Modified: Feb. 26, 2026, 5:49 p.m.

4.1

CVSS3.1

CVE-2025-42935 - Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Commun…

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the a…

📅 Published: Aug. 12, 2025, 2:05 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-42934 - CRLF Injection vulnerability in SAP S/4HANA (Supplier invoice)

SAP S/4HANA Supplier invoice is vulnerable to CRLF Injection. An attacker with user-level privileges can bypass the allowlist and insert untrusted sites into the 'Trusted Sites' configuration by injecting line feed (LF) characters into application inputs. This vulnerability has a low impact on the …

📅 Published: Aug. 12, 2025, 2:04 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-38500 - xfrm: interface: fix use-after-free after changing collect_md xfrm interface

In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md xfrm interface collect_md property on xfrm interfaces can only be set on device creation, thus xfrmi_changelink() should fail when called on such interfaces. The chec…

📅 Published: Aug. 12, 2025, midnight 🔄 Last Modified: Jan. 7, 2026, 4:26 p.m.
Total resulsts: 349182
Page 4346 of 34,919
« previous page » next page
Filters