Vulnerability Description
SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On successful exploitation, this results in the crash of the target component. Multiple submissions can make the target completely unavailable. A similarly crafted submission can be used to perform an out-of-bounds read operation as well, revealing sensitive information that is loaded in memory at that time. There is no ability to modify any information.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-42976?
CVE-2025-42976 is a vulnerability with a CVSS score of 8.1 (HIGH). SAP NetWeaver Application Server ABAP (BIC Document) allows an authenticated attacker to craft a request that, when submitted to a BIC Document application, could cause a memory corruption error. On s...
How severe is CVE-2025-42976?
CVE-2025-42976 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-42976?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.