CSRF Vulnerability in SAP NetWeaver Application Server for ABAP
CVE-2025-42908
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 October 2025
What is CVE-2025-42908?
A Cross-Site Request Forgery (CSRF) vulnerability in the SAP NetWeaver Application Server for ABAP allows authenticated attackers to craft requests that can bypass critical transaction authorization checks. By exploiting this vulnerability, attackers can initiate transactions directly through the session manager, gaining access to restricted functionalities without proper permissions. This could jeopardize the integrity and confidentiality of sensitive data while having no direct impact on system availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP NetWeaver Application Server for ABAP KRNL64UC 7.53
SAP NetWeaver Application Server for ABAP KERNEL 7.53
SAP NetWeaver Application Server for ABAP 7.54
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved