---
id: CVE-2025-42872
title: >-
  Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise
  Portal, an unauthenticated attacker could inject malicious scripts that
  execute in the context of other users� browsers, allowing the attacker to
  steal session…
summary: >-
  Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise
  Portal, an unauthenticated attacker could inject malicious scripts that
  execute in the context of other users� browsers, allowing the attacker to
  steal session…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-489
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42872'
references:
  - url: 'https://me.sap.com/notes/3662622'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00259
epssPercentile: 0.16083
ingestedAt: '2026-10-07T20:46:46.793Z'
---

## Overview

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability has a low impact on confidentiality and integrity and no impact on availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
