CVE-2025-42990

LOW

SAPUI5 applications - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are not impacted.

References (2)

Core 2
Core References

Scores

CVSS v3 3.0
EPSS 0.0014
EPSS Percentile 33.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (7)
SAP_SE/SAPUI5 applications 754
SAP_SE/SAPUI5 applications 755
SAP_SE/SAPUI5 applications 756
SAP_SE/SAPUI5 applications 757
SAP_SE/SAPUI5 applications 758
SAP_SE/SAPUI5 applications SAP_UI 750
SAP_SE/SAPUI5 applications UI_700 200
Published Jun 10, 2025
Tracked Since Feb 18, 2026