Security Advisory
CVE-2025-42902
5.3
MEDIUM
Vulnerability Description
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the availability but no impact on the confidentiality and integrity.
Published Date
October 14, 2025
Official Source
NIST NVD Advisory