PT-2024-10081 · Sap · Sap Netweaver As For Abap/Abap Platform

Published

2024-05-12

·

Updated

2025-10-23

·

CVE-2025-0066

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The affected software is SAP NetWeaver AS for ABAP and ABAP Platform, specifically the Internet Communication Framework. This issue arises from weak access controls, allowing attackers to access restricted information and potentially compromising application integrity, confidentiality, and availability. An exploit for this issue can be used to access data within the application.
The vulnerable software versions are not explicitly stated, but the issue is reported to affect SAP services, including SQL injection, improper authentication, and DLL hijacking.
More information can be found at the provided links, including the vendor's advisory. #SAPNetWeaver #ABAPPlatform #InternetCommunicationFramework #cybersecurity #SAPvulnerabilities #accesscontrols #dataexposure #SQLinjection #improperauthentication #DLLhijacking

Fix

Incorrect Permission

Weakness Enumeration

Related Identifiers

BDU:2025-00254
CVE-2025-0066

Affected Products

Sap Netweaver As For Abap/Abap Platform