← Back to browse · API

CVE-2025-0070

Severity
CRITICAL
CVSS
9.9
EPSS
0.00701
Risk score
39.85
CISA KEV
No
PoC
No
Published
2025-01-14
Modified
2025-01-14
First seen
2026-08-07
Aliases
EUVD-2025-1499, GHSA-7P2R-987W-F5Q7
Products
SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 7.22EXT, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 7.53, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 7.54, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 7.77, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 7.89, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 7.93, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 7.97, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 8.04, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 9.12, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 9.13, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform 9.14, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform KERNEL 7.22, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform KRNL64NUC 7.22, SAP_SE:SAP NetWeaver Application Server for ABAP and ABAP Platform KRNL64UC 7.22
Sources
euvd EUVD-2025-1499

Description

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability.

References