Due to incorrect memory address handling in ABAP SQL of SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker with high privileges could execute certain forms of SQL queries leading to manipulation of content in the output variable. This vulnerability has a low impact on the confidentiality, integrity and the availability of the application.
We have discovered 27 live websites that are affected by CVE-2025-30015.
| Product | |
| Category | Web Application Server |
| Vulnerable Domains | 27 live websites (19% of NetWeaver Application Server install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1 versions ( 13% of all versions) |
| 14 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 12 websites |
| .com.cn | 1 websites |
| .de | 1 websites |
| .it | 1 websites |
| .net | 1 websites |
| .org | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.***.*********.gov | *,***,*** | ||
| ***.**.gov | *,***,*** | ||
| **************.***.*********.gov | *,***,*** | ||
| ********.******.com | *,***,*** | ||
| ***************.com | *,***,*** | ||
| ******.*****.**.gov | *,***,*** | ||
| ***********.*****.com | *,***,*** | ||
| ***.*************.com | *,***,*** | ||
| *****.*******.***.cn | **,***,*** | ||
| *********.*********.it | **,***,*** |
FAQ