CVE-2025-42954: SAP SE SAP NetWeaver Business Warehouse Ccaw Application

Low severity, CVSS 2.7. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected resource. This leads to low impact on availability of the application, there is no impact on confidentiality and integrity.

Affected products

  • SAP SE SAP NetWeaver Business Warehouse Ccaw Application: version 200 only; version 300 only; version 400 only; version 701 only; version 702 only; version 731 only; …

Published 2025-07-08. Last modified 2026-06-17.