Memory Corruption Vulnerability in SAP NetWeaver ABAP Platform
CVE-2025-42902
5.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-42902?
A memory corruption vulnerability exists in SAP NetWeaver AS ABAP and ABAP Platform that allows unauthenticated attackers to send a malformed SAP Logon Ticket or SAP Assertion Ticket to the application server. This leads to a de-referencing of NULL, causing the work process to crash. While this issue may affect availability, it does not compromise the confidentiality or integrity of the system. Organizations using affected versions should implement recommended security updates promptly to minimize potential disruptions.
Affected Version(s)
SAP Netweaver AS ABAP and ABAP Platform KRNL64NUC 7.22
SAP Netweaver AS ABAP and ABAP Platform 7.22EXT
SAP Netweaver AS ABAP and ABAP Platform KRNL64UC 7.22