CVE-2025-42959
8.1SAP SE · NetWeaver ABAP Server and ABAP Platform
An unauthenticated attacker can reuse captured HMAC credentials from unpatched systems to perform replay attacks, potentially leading to full system compromise.
Executive summary
An unauthenticated attacker can perform replay attacks against SAP NetWeaver ABAP systems using stolen HMAC credentials, posing a critical risk of full system compromise.
Vulnerability
This vulnerability involves the use of single-factor authentication (CWE-308) where an unauthenticated attacker can intercept and replay HMAC credentials. This allows the attacker to bypass authentication mechanisms and execute unauthorized actions on the target system.
Business impact
The potential impact of this vulnerability is severe, as it can lead to complete system compromise, affecting the confidentiality, integrity, and availability of critical business data. Given the CVSS score of 8.1, this represents a high-risk security flaw that could lead to unauthorized access to sensitive financial or operational records stored within the SAP environment.
Remediation
Immediate Action: Review the official SAP Security Note 3600846 and apply the recommended security patches to all affected SAP_BASIS components immediately.
Proactive Monitoring: Monitor system access logs for anomalous authentication patterns or repeated failed attempts that may indicate credential replay activity.
Compensating Controls: Ensure that network traffic between interconnected SAP systems is encrypted and restricted to authorized segments to prevent the interception of authentication tokens.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a significant threat to the security posture of SAP environments due to the potential for full system compromise. Administrators must prioritize the application of vendor-supplied patches and ensure that all instances of the affected SAP_BASIS versions are updated to a secure state to mitigate the risk of credential replay attacks.