CVE-2025-42908 - CVE House
Back to Database
Status published Medium CVE-2025-42908

Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP

Vulnerability Description

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate transactions directly via the session manager, bypassing the first transaction screen and the associated authorization check. This vulnerability could allow the attacker to perform actions and execute transactions that would normally require specific permissions, compromising the integrity and confidentiality of the system by enabling unauthorized access to restricted functionality. There is no impact to availability from this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-42908

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SAP NetWeaver Application Server for ABAP
Vulnerable Versions:
KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.16

Timeline

Official Publish: October 14th, 2025
Last Modified: October 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)