CVE-2025-42908
- EPSS 0.02%
- Veröffentlicht 14.10.2025 00:18:04
- Zuletzt bearbeitet 14.10.2025 19:36:29
Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated a...
CVE-2025-42902
- EPSS 0.07%
- Veröffentlicht 14.10.2025 00:17:32
- Zuletzt bearbeitet 14.10.2025 19:36:29
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which ...
- EPSS 0.1%
- Veröffentlicht 09.09.2025 02:15:42
- Zuletzt bearbeitet 12.11.2025 19:15:36
Due to a deserialization vulnerability in SAP NetWeaver, an unauthenticated attacker could exploit the system through the RMI-P4 module by submitting malicious payload to an open port. The deserialization of such untrusted Java objects could lead to ...
CVE-2025-42938
- EPSS 0.11%
- Veröffentlicht 09.09.2025 02:15:41
- Zuletzt bearbeitet 09.09.2025 16:28:43
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is pro...
CVE-2025-42926
- EPSS 0.08%
- Veröffentlicht 09.09.2025 02:15:41
- Zuletzt bearbeitet 23.10.2025 12:43:32
SAP NetWeaver Application Server Java does not perform an authentication check when an attacker attempts to access internal files within the web application.Upon successfully exploitation, an unauthenticated attacker could access these files to gathe...
CVE-2025-42927
- EPSS 0.02%
- Veröffentlicht 09.09.2025 02:15:41
- Zuletzt bearbeitet 09.09.2025 16:28:43
SAP NetWeaver AS Java application uses Adobe Document Service, installed with a vulnerable version of OpenSSL.Successful exploitation of known vulnerabilities in the outdated OpenSSL library would allow user with high system privileges to access and ...
CVE-2025-42925
- EPSS 0.04%
- Veröffentlicht 09.09.2025 02:15:40
- Zuletzt bearbeitet 09.09.2025 16:28:43
Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of severa...
CVE-2025-42922
- EPSS 0.09%
- Veröffentlicht 09.09.2025 02:15:40
- Zuletzt bearbeitet 09.09.2025 16:28:43
SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availabilit...
CVE-2025-42918
- EPSS 0.03%
- Veröffentlicht 09.09.2025 02:15:40
- Zuletzt bearbeitet 23.10.2025 12:44:38
SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availab...
CVE-2025-42911
- EPSS 0.03%
- Veröffentlicht 09.09.2025 02:15:38
- Zuletzt bearbeitet 23.10.2025 12:45:48
SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no eff...