SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target completely unavailable. A similarly crafted submission can be used to perform an out-of-bounds read operation as well, revealing sensitive information that is loaded in memory at that time. There is no ability to modify any information.
History

Tue, 12 Aug 2025 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap netweaver
Sap netweaver Application Server For Abap
Vendors & Products Sap
Sap netweaver
Sap netweaver Application Server For Abap

Tue, 12 Aug 2025 02:30:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target completely unavailable. A similarly crafted submission can be used to perform an out-of-bounds read operation as well, revealing sensitive information that is loaded in memory at that time. There is no ability to modify any information.
Title Multiple vulnerabilities in SAP NetWeaver Application Server ABAP (BIC Document)
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-08-12T02:10:06.835Z

Updated: 2025-08-13T20:19:41.155Z

Reserved: 2025-04-16T13:25:45.231Z

Link: CVE-2025-42976

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-12T03:15:28.603

Modified: 2025-08-12T14:25:33.177

Link: CVE-2025-42976

cve-icon Redhat

No data.