CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.3. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-42902
Severity
MEDIUM
CVSS
5.3
EPSS
0.36%
Original NVD Description
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the availability but no impact on the confidentiality and integrity.