cbcvebase.
CVE-2025-0066
published 2025-01-14

CVE-2025-0066: Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due…

PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.55%
42.4th percentile
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sap_sesap_netweaver_as_for_abap_and_abap_platform
sap_sesap_netweaver_as_for_abap_and_abap_platform
sap_sesap_netweaver_as_for_abap_and_abap_platform
sap_sesap_netweaver_as_for_abap_and_abap_platform
sap_sesap_netweaver_as_for_abap_and_abap_platform
sap_sesap_netweaver_as_for_abap_and_abap_platform
sap_sesap_netweaver_as_for_abap_and_abap_platform
sap_sesap_netweaver_as_for_abap_and_abap_platform
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.