CVE-2025-0066Incorrect Permission Assignment in SE SAP Netweaver AS FOR Abap AND Abap Platform

Severity
8.8HIGHNVD
CNA9.9
EPSS
0.1%
top 73.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14

Description

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDsap/sap_basis17 versions+16

Patches

🔴Vulnerability Details

2
CVEList
Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework)2025-01-14
GHSA
GHSA-26rp-5gjf-gw47: Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted inform2025-01-14
CVE-2025-0066 — Incorrect Permission Assignment | cvebase