CVE-2025-42976: SAP SE SAP NetWeaver Application Server Abap Bic Document
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target completely unavailable. A similarly crafted submission can be used to perform an out-of-bounds read operation as well, revealing sensitive information that is loaded in memory at that time. There is no ability to modify any information.
Affected products
- SAP SE SAP NetWeaver Application Server Abap Bic Document: version S4COREOP 104 only; version 105 only; version 106 only; version 107 only; version 108 only; version 602 only; …
Published 2025-08-12. Last modified 2026-06-17.