CVE-2025-42902
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-10-14
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | netweaver | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-476 | The product dereferences a pointer that it expects to be valid but is NULL. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a memory corruption issue in SAP NetWeaver AS ABAP and ABAP Platform where an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This causes a NULL pointer dereference, leading to a crash of the work process.
How can this vulnerability impact me? :
The impact of this vulnerability is low on availability because it causes the work process to crash. However, it does not affect confidentiality or integrity of the system.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability does not impact confidentiality or integrity, so it is unlikely to affect compliance with standards and regulations such as GDPR or HIPAA that focus on protecting data privacy and integrity.