Memory Corruption Vulnerability in SAP NetWeaver ABAP Platform
CVE-2025-42902

5.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
14 October 2025

What is CVE-2025-42902?

A memory corruption vulnerability exists in SAP NetWeaver AS ABAP and ABAP Platform that allows unauthenticated attackers to send a malformed SAP Logon Ticket or SAP Assertion Ticket to the application server. This leads to a de-referencing of NULL, causing the work process to crash. While this issue may affect availability, it does not compromise the confidentiality or integrity of the system. Organizations using affected versions should implement recommended security updates promptly to minimize potential disruptions.

Affected Version(s)

SAP Netweaver AS ABAP and ABAP Platform KRNL64NUC 7.22

SAP Netweaver AS ABAP and ABAP Platform 7.22EXT

SAP Netweaver AS ABAP and ABAP Platform KRNL64UC 7.22

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.