---
id: CVE-2025-42901
title: >-
  SAP Application Server for ABAP allows an authenticated attacker to store
  malicious JavaScript payloads which could be executed in victim user's browser
  when accessing the affected functionality of BAPI explorer
summary: >-
  SAP Application Server for ABAP allows an authenticated attacker to store
  malicious JavaScript payloads which could be executed in victim user's browser
  when accessing the affected functionality of BAPI explorer. This has low
  impact on c…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-94
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42901'
references:
  - url: 'https://me.sap.com/notes/3652788'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00226
epssPercentile: 0.12271
ingestedAt: '2026-10-08T11:31:27.362Z'
---

## Overview

SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on confidentiality and integrity with no impact on availability of the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
