Back to overview

CVE-2025-0070

CRITICAL
9.9
CVSS 3.1
Description
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability.

Metadata

CVE ID
CVE-2025-0070
State
PUBLISHED
Assigner
sap
Reserved
2024-12-11 05:05 UTC
Published
2025-01-14 00:10 UTC
Last updated
2025-01-14 15:02 UTC
Primary CWE
CWE-287
CWE-287: (Improper Authentication)
Vendor / Product
SAP_SE / SAP NetWeaver Application Server for ABAP and ABAP Platform
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SAP_SE SAP NetWeaver Application Server for ABAP and ABAP Platform KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53 …
Weakness (CWE)
CWESourceDescription
CWE-287 cna CWE-287: (Improper Authentication)
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview