CVE-2025-42958: SAP SE SAP NetWeaver
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.
Affected products
- SAP SE SAP NetWeaver: version 7.22EXT only; version 7.53 only; version 7.54 only
Published 2025-09-09. Last modified 2026-06-17.