← Vulnerability feed

Vulnerability record · CVE-2025-0066 · published 14 January 2025

CVE-2025-0066: Sap basis incorrect permission assignment vulnerability

Sap · Sap Basis

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

8.8 CVSS 3.1 High EPSS 0.58% · top 54.6% CWE-732 · Incorrect permission assignment
8.8CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-0066 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2024-34687Sap basis cross-site scripting vulnerabilitySAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS…EPSS 0.40%8.8CVE-2026-23687Sap basis improper verification of cryptographic signature vulnerabilitySAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and …EPSS 0.48%8.8CVE-2025-0063Sap basis sql injection vulnerabilitySAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attack…EPSS 0.75%7.5CVE-2025-23193Sap basis vulnerabilitySAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the ex…EPSS 0.35%7.5CVE-2016-4551Sap netweaver improper access control vulnerabilityThe (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to …EPSS 1.4%6.5CVE-2026-0484Sap basis open redirect vulnerabilityDue to missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA, an authenticated attacker could access a specific transa…EPSS 0.28%6.5CVE-2025-0058Sap basis insecure direct object reference vulnerabilityIn SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request …EPSS 0.34%6.1CVE-2025-42956Sap basis cross-site scripting vulnerabilitySAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to create a malicious link which they can make publicly av…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2025-0066), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.