CVE-2025-42902: SAP SE SAP NetWeaver As Abap And Abap Platform
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the availability but no impact on the confidentiality and integrity.
Affected products
- SAP SE SAP NetWeaver As Abap And Abap Platform: version 7.22EXT only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.89 only; version 7.93 only; …
Published 2025-10-14. Last modified 2026-10-08.