PT-2024-10300 · Sap · Sap Netweaver Application Server Abap+1

Published

2024-05-12

·

Updated

2025-02-07

·

CVE-2025-0070

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The affected software is SAP NetWeaver Application Server for ABAP and ABAP Platform, which allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. This can result in potential security concerns and has a high impact on confidentiality, integrity, and availability. An exploit for this issue is available, posing high risks to the system's security. The vulnerable software is SAP NetWeaver Application Server for ABAP and ABAP Platform. It is worth noting that the provided links may contain more detailed information about the issue and the available exploit. #SAPNetWeaver #ABAP #PrivilegeEscalation #ImproperAuthentication #Cybersecurity #AuthenticationFlaw

Fix

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-00729
CVE-2025-0070

Affected Products

Abap Platform
Sap Netweaver Application Server Abap