CVE-2025-42961
- EPSS 0.03%
- Veröffentlicht 08.07.2025 00:35:26
- Zuletzt bearbeitet 08.07.2025 16:18:14
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access sensitive database tables. By leveraging overly perm...
CVE-2025-42959
- EPSS 0.11%
- Veröffentlicht 08.07.2025 00:35:03
- Zuletzt bearbeitet 08.07.2025 16:18:14
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target sy...
CVE-2025-42953
- EPSS 0.04%
- Veröffentlicht 08.07.2025 00:34:41
- Zuletzt bearbeitet 08.07.2025 16:18:14
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of ...
CVE-2025-42989
- EPSS 0.05%
- Veröffentlicht 10.06.2025 00:12:16
- Zuletzt bearbeitet 12.06.2025 16:06:39
RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the applicatio...
CVE-2025-31325
- EPSS 0.08%
- Veröffentlicht 10.06.2025 00:10:30
- Zuletzt bearbeitet 12.06.2025 16:06:39
Due to a Cross-Site Scripting vulnerability in SAP NetWeaver (ABAP Keyword Documentation), an unauthenticated attacker could inject malicious JavaScript into a web page through an unprotected parameter. When a victim accesses the affected page, the s...
CVE-2025-42999
- EPSS 31.52%
- Veröffentlicht 13.05.2025 00:17:43
- Zuletzt bearbeitet 31.10.2025 21:58:56
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the hos...
CVE-2025-31329
- EPSS 0.04%
- Veröffentlicht 13.05.2025 00:16:51
- Zuletzt bearbeitet 13.05.2025 19:35:25
SAP NetWeaver is vulnerable to an Information Disclosure vulnerability caused by the injection of malicious instructions into user configuration settings. An attacker with administrative privileges can craft these instructions so that when accessed b...
CVE-2025-31324
- EPSS 45.8%
- Veröffentlicht 24.04.2025 16:50:27
- Zuletzt bearbeitet 31.10.2025 21:56:14
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect...
CVE-2025-30015
- EPSS 0.04%
- Veröffentlicht 08.04.2025 07:14:37
- Zuletzt bearbeitet 08.04.2025 18:13:53
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the out...
CVE-2025-27437
- EPSS 0.04%
- Veröffentlicht 08.04.2025 07:13:58
- Zuletzt bearbeitet 08.04.2025 18:13:53
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access bu...