CVE-2025-42902 (CNNVD-202510-2083)
中文标题:
SAP NetWeaver AS ABAP Business Server和SAP ABAP Platform 代码问题漏洞
英文标题:
Memory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP Platform
漏洞描述
中文描述:
SAP NetWeaver AS ABAP Business Server和SAP ABAP Platform都是德国思爱普(SAP)公司的产品。SAP NetWeaver AS ABAP Business Server是一款适用于ABAP(高级商务应用编程)的应用服务器。SAP ABAP Platform是一个基于 ABAP 的 SAP 解决方案。 SAP NetWeaver AS ABAP Business Server和SAP ABAP Platform存在代码问题漏洞,该漏洞源于内存损坏漏洞,可能导致工作进程崩溃,影响可用性。
英文描述:
Due to the memory corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform, an unauthenticated attacker can send a corrupted SAP Logon Ticket or SAP Assertion Ticket to the SAP application server. This leads to a dereference of NULL which makes the work process crash. As a result, it has a low impact on the availability but no impact on the confidentiality and integrity.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | KRNL64NUC 7.22 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:krnl64nuc_7.22:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 7.22EXT | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:7.22ext:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | KRNL64UC 7.22 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:krnl64uc_7.22:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 7.53 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:7.53:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | KERNEL 7.22 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:kernel_7.22:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 7.54 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:7.54:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 7.77 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:7.77:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 7.89 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:7.89:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 7.93 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:7.93:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 9.14 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:9.14:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 9.15 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:9.15:*:*:*:*:*:*:*
|
| SAP_SE | SAP Netweaver AS ABAP and ABAP Platform | 9.16 | - | - |
cpe:2.3:a:sap_se:sap_netweaver_as_abap_and_abap_platform:9.16:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-42902 |
2025-11-11 15:23:21 | 2025-11-11 07:40:31 |
| NVD | nvd_CVE-2025-42902 |
2025-11-11 15:01:05 | 2025-11-11 07:48:20 |
| CNNVD | cnnvd_CNNVD-202510-2083 |
2025-11-11 15:12:29 | 2025-11-11 08:00:17 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 代码问题
- cnnvd_id: 未提取 -> CNNVD-202510-2083
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']