SAP NetWeaver and ABAP Platform ABAP SQL Memory Address Handling Vulnerability Allowing SQL Injection

Vulnerability

A vulnerability exists in the ABAP SQL processing of SAP NetWeaver and the ABAP Platform (Application Server ABAP). This issue arises from improper management of memory addresses, which could enable an authenticated attacker with high privileges to execute specific SQL queries. Exploitation of this vulnerability could lead to unauthorized manipulation of content in the output variable. While the vulnerability has been assessed as having a low impact on the application's confidentiality, integrity, and availability, it still poses a risk that should be addressed.

Impact

Exploitation of this vulnerability could result in unauthorized manipulation of output variables, potentially leading to misleading or incorrect information being presented to users or systems.

Remediation

Users are advised to consult the SAP Security Notes and implement the recommended patches. This vulnerability will be addressed in the upcoming SAP Security Patch Day.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
3.8
remediation
5.6
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.