VYPR
Low severity3.0NVD Advisory· Published Jun 10, 2025· Updated Apr 15, 2026

CVE-2025-42990

CVE-2025-42990

Description

Unprotected SAPUI5 applications allow an attacker with basic privileges to inject malicious HTML code into a webpage, with the goal of redirecting users to the attacker controlled URL. This issue could impact the integrity of the application. Confidentiality or Availability are not impacted.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CVE-2025-42990 is a low-severity vulnerability in SAPUI5 applications that allows an attacker to inject malicious HTML and redirect users to an attacker-controlled URL.

Vulnerability

Description

CVE-2025-42990 describes an insufficient input sanitization issue in SAPUI5 applications that permits HTML injection. An attacker with basic privileges can embed arbitrary HTML code into a vulnerable webpage, which may then be rendered in a user's browser. This vulnerability stems from improper handling of user-supplied content within the application's output generation [1].

Exploitation

Prerequisites

To exploit this flaw, the attacker must already have basic privileges on the target SAP system, meaning they can authenticate and submit crafted input. No additional network position or user interaction beyond normal page rendering is required for the injected HTML to be delivered to other users. The attack surface is limited to UI components that reflect or reuse user input without adequate encoding [1].

Impact

Assessment

Successful exploitation enables the attacker to inject malicious HTML that can redirect victims to an attacker-controlled URL, undermining the integrity of the application's display. According to the official description, confidentiality and availability are not affected, so the primary risk is phishing-style attacks that manipulate what users see, potentially leading to credential theft or other social engineering outcomes [1].

Mitigation

Status

SAP addresses this vulnerability through its monthly Security Patch Day process. The vendor recommends implementing the corresponding SAP Security Note, which is available in the SAP for Me portal. Since the severity is Low, the fix is included in the newest support package for mainstream and extended maintenance releases. Users should apply the provided patches as soon as feasible to prevent misuse [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.