8.8

CVE-2025-0063

SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform

SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Sap Basis Version 700
SAP ≫ Sap Basis Version 701
SAP ≫ Sap Basis Version 702
SAP ≫ Sap Basis Version 731
SAP ≫ Sap Basis Version 740
SAP ≫ Sap Basis Version 750
SAP ≫ Sap Basis Version 751
SAP ≫ Sap Basis Version 752
SAP ≫ Sap Basis Version 753
SAP ≫ Sap Basis Version 754
SAP ≫ Sap Basis Version 755
SAP ≫ Sap Basis Version 756
SAP ≫ Sap Basis Version 757
SAP ≫ Sap Basis Version 758
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.75% 0.513
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
SAP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://url.sap/sapsecuritypatchday
Patch
https://me.sap.com/notes/3550816
Permissions Required