CVE-2025-42872
MEDIUMDescription
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2025-42872? +
How severe is CVE-2025-42872? +
How do I check if I'm vulnerable to CVE-2025-42872? +
Related Vulnerabilities
A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with …
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable …
Active Debug Code in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, …
Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an …
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web …
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication …