CVE-2025-42959: SAP SE SAP NetWeaver Abap Server And Abap Platform
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.
Affected products
- SAP SE SAP NetWeaver Abap Server And Abap Platform
Published 2025-07-08. Last modified 2026-06-17.