First published: Tue Apr 08 2025(Updated: )
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the confidentiality, integrity and the availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | ||
SAP ABAP | ||
SAP Application Server ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30015 is classified as a high severity vulnerability due to the potential for unauthorized SQL manipulation.
To fix CVE-2025-30015, apply the latest security patches available from SAP for affected products.
Affected products for CVE-2025-30015 include SAP NetWeaver, SAP ABAP Platform, and SAP Application Server ABAP.
Exploitation of CVE-2025-30015 allows authenticated attackers to execute specific SQL queries, potentially manipulating output variables.
Organizations using the affected SAP products with high privileged accounts are at risk from CVE-2025-30015.