CVE-2025-0066: Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework)

9.9 CVSS

Description

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

Classification

CVE ID: CVE-2025-0066

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.9

Affected Products

Vendor: SAP_SE

Product: SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework)

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-12 (when was this score calculated)

References

https://me.sap.com/notes/3550708
https://url.sap/sapsecuritypatchday

Timeline