CVE-2025-42925
- EPSS 0.23%
- Veröffentlicht 09.09.2025 02:15:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
Due to the lack of randomness in assigning Object Identifiers in the SAP NetWeaver AS JAVA IIOP service, an authenticated attacker with low privileges could predict the identifiers by conducting a brute force search. By leveraging knowledge of severa...
CVE-2025-42911
- EPSS 0.21%
- Veröffentlicht 09.09.2025 02:15:38
- Zuletzt bearbeitet 23.10.2025 12:45:48
SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no eff...
CVE-2025-42948
- EPSS 0.22%
- Veröffentlicht 12.08.2025 02:08:17
- Zuletzt bearbeitet 15.04.2026 00:35:42
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is process...
CVE-2025-42945
- EPSS 0.2%
- Veröffentlicht 12.08.2025 02:05:51
- Zuletzt bearbeitet 15.04.2026 00:35:42
SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker could craft a URL with malicious script as payload and trick a victim with active user session into executing it. Upon successful exploit, this vulnerabi...
CVE-2025-42942
- EPSS 0.22%
- Veröffentlicht 12.08.2025 02:05:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
SAP NetWeaver Application Server for ABAP has cross-site scripting vulnerability. Due to this, an unauthenticated attacker could craft a URL embedded with malicious script and trick an unauthenticated victim to click on it to execute the script. Upon...
CVE-2025-42936
- EPSS 0.18%
- Veröffentlicht 12.08.2025 02:05:19
- Zuletzt bearbeitet 23.10.2025 12:41:58
The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to pr...
CVE-2025-42935
- EPSS 0.14%
- Veröffentlicht 12.08.2025 02:05:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This lea...
CVE-2025-42986
- EPSS 0.22%
- Veröffentlicht 08.07.2025 00:38:32
- Zuletzt bearbeitet 27.10.2025 16:55:48
Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low i...
CVE-2025-42981
- EPSS 0.21%
- Veröffentlicht 08.07.2025 00:38:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script execut...
CVE-2025-42980
- EPSS 0.76%
- Veröffentlicht 08.07.2025 00:38:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability o...