- Description
- SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target completely unavailable. A similarly crafted submission can be used to perform an out-of-bounds read operation as well, revealing sensitive information that is loaded in memory at that time. There is no ability to modify any information.
- Source
- cna@sap.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Severity
- HIGH
- cna@sap.com
- CWE-125
- Hype score
- Not currently trending
CVE-2025-42976 (CVSS:8.1, HIGH) is Awaiting Analysis. SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when subm..https://t.co/oZC7StcMdo #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
17 Aug 2025
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-42976 SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cau… https://t.co/dGFf3f8QOc
@CVEnew
12 Aug 2025
295 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes