4.1
CVE-2025-30015
- EPSS 0.04%
- Veröffentlicht 08.04.2025 07:14:37
- Zuletzt bearbeitet 08.04.2025 18:13:53
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the confidentiality, integrity and the availability of the application.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP NetWeaver and ABAP Platform (Application Server ABAP)
Default Statusunaffected
Version
KRNL64UC 7.53
Status
affected
Version
KERNEL 7.53
Status
affected
Version
7.54
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.123 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 4.1 | 0.7 | 3.4 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.