Back

MEDIUM

Memory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP Platform

Published Oct 14, 2025

Description

Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the availability but no impact on the confidentiality and integrity.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner sap
Published Oct 14, 2025
Updated Oct 14, 2025
Reserved Apr 16, 2025

CISA Vulnrichment

Updated Oct 14, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner sap
Published Oct 14, 2025
Updated Oct 14, 2025

GitHub

No data