CVE-2025-30015
Last modified
CVE-2025-30015 is a medium-severity vulnerability rated 4.1/10 on the CVSS scale. Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the confidentiality, integrity and the availability of the application.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the confidentiality, integrity and the availability of the application.
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-30015?
How severe is CVE-2025-30015?
How do I fix CVE-2025-30015?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-3001A vulnerability classified as critical was found in PyTorch …5.3
- CVE-2025-30010The Live Auction Cockpit in SAP Supplier Relationship Manage…6.1
- CVE-2025-30011The Live Auction Cockpit in SAP Supplier Relationship Manage…5.3
- CVE-2025-30012The Live Auction Cockpit in SAP Supplier Relationship Manage…9.8
- CVE-2025-30013SAP ERP BW Business Content is vulnerable to OS Command Inje…6.7
- CVE-2025-30014SAP Capital Yield Tax Management has directory traversal vul…7.7
- CVE-2025-30016SAP Financial Consolidation allows an unauthenticated attack…9.8
- CVE-2025-30017Due to a missing authorization check, an authenticated attac…4.4
- CVE-2025-30018The Live Auction Cockpit in SAP Supplier Relationship Manage…7.5
- CVE-2025-3002A vulnerability, which was classified as critical, has been …7.3
- CVE-2025-30022CM Soluces Informatica Ltda Auto Atendimento 1.x.x was disco…6.8
- CVE-2025-30023The communication protocol used between client and server ha…9
Are you affected by CVE-2025-30015?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
