CVE-2025-42976

8.1

SAP · NetWeaver Application Server ABAP (BIC Document)

An authenticated attacker can trigger memory corruption in SAP NetWeaver Application Server ABAP (BIC Document), leading to service crashes or unauthorized information disclosure.

Executive summary

An authenticated attacker can exploit a memory corruption vulnerability in SAP NetWeaver Application Server ABAP to cause denial of service or access sensitive memory contents.

Vulnerability

This vulnerability involves an out-of-bounds read and memory corruption flaw triggered via crafted requests. It requires an authenticated user to successfully interact with the BIC Document application to achieve the impact.

Business impact

Successful exploitation poses a significant risk to operational continuity and data confidentiality. By causing repeated crashes, an attacker can render critical business processes unavailable, while the out-of-bounds read capability allows for the potential exposure of sensitive information residing in memory. With a CVSS score of 8.1, this represents a high-severity risk that could compromise the integrity of business operations and protected data.

Remediation

Immediate Action: Consult SAP Security Note 3611184 to identify and apply the specific vendor patches or configuration changes required for your environment.

Proactive Monitoring: Monitor application and system logs for repeated crash events, memory error exceptions, or unusual request patterns directed at the BIC Document component.

Compensating Controls: Implement stricter access controls for the BIC Document application to minimize the number of users capable of submitting requests, and utilize network-level monitoring to detect anomalous traffic volume.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for service disruption, organizations should prioritize reviewing SAP Security Note 3611184 immediately. Security teams must ensure that all affected SAP instances are patched or mitigated according to vendor guidelines to prevent potential information disclosure and unauthorized service degradation.

More SAP CVEs

Sources