Medium - CVE-2025-42969 - SAP NetWeaver Application Server ABAP and ABAP...
SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject a malicious script into a dynamically crafted URL. The victim, when tricked into clicking on...
Medium - CVE-2025-42970 - SAPCAR improperly sanitizes the file paths...
SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high...
Medium - CVE-2025-42971 - A memory corruption vulnerability exists in...
A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it gets processed by...
Medium - CVE-2025-42973 - Due to a Cross-Site Scripting vulnerability in...
Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By...
Medium - CVE-2025-42974 - Due to missing authorization check, an attacker...
Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally restricted,...
Low - CVE-2025-42978 - The widely used component that establishes...
The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the...
Medium - CVE-2025-42979 - The GuiXT application, which is integrated with...
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC....
Critical - CVE-2025-42980 - SAP NetWeaver Enterprise Portal Federated...
SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a...
Medium - CVE-2025-42981 - Due to an open redirect vulnerability in SAP...
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized....
Medium - CVE-2025-42985 - Due to insufficient sanitization in the SAP...
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim?s browser. This could potentially...