High - CVE-2025-42953 - SAP Netweaver System Configuration does not...
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity...
Low - CVE-2025-42954 - SAP NetWeaver Business Warehouse CCAW...
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in...
High - CVE-2025-42959 - An unauthenticated attacker may exploit a...
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay...
Medium - CVE-2025-42960 - SAP Business Warehouse and SAP BW/4HANA BEx...
SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially...
Medium - CVE-2025-42961 - Due to a missing authorization check in SAP...
Due to a missing authorization check in SAP NetWeaver Application server for ABAP, an authenticated user with high privileges could exploit the insufficient validation of user permissions to access...
Medium - CVE-2025-42962 - SAP Business Warehouse (Business Explorer Web)...
SAP Business Warehouse (Business Explorer Web) allows an attacker to create a malicious link. If an authenticated user clicks on this link, the injected script gets executed within the scope of...
Critical - CVE-2025-42963 - A critical vulnerability in SAP NetWeaver...
A critical vulnerability in SAP NetWeaver Application server for Java Log Viewer enables authenticated administrator users to exploit unsafe Java object deserialization. Successful exploitation can...
Critical - CVE-2025-42964 - SAP NetWeaver Enterprise Portal Administration...
SAP NetWeaver Enterprise Portal Administration is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of...
Medium - CVE-2025-42965 - SAP CMC Promotion Management allows an...
SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for...
Critical - CVE-2025-42966 - SAP NetWeaver XML Data Archiving Service allows...
SAP NetWeaver XML Data Archiving Service allows an authenticated attacker with administrative privileges to exploit an insecure Java deserialization vulnerability by sending a specially crafted...