Memory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP Platform
Published Oct 14, 2025
5.3
MEDIUMCVSS 3.1
EPSS 0.37%
Description
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the availability but no impact on the confidentiality and integrity.
Affected products
-
Affected
- 7.22EXT
- 7.53
- 7.54
- 7.77
- 7.89
- 7.93
- 9.14
- 9.15
- 9.16
- KERNEL 7.22
- KRNL64NUC 7.22
- KRNL64UC 7.22
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| SAP SE | SAP Netweaver AS ABAP and ABAP Platform | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data