# CVE-2025-42959

## Summary

- **CVE ID:** CVE-2025-42959
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-308
- **Published:** Jul 8, 2025
- **Last Modified:** Mar 13, 2026

## Description

An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.

## Affected Products

- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 700)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 701)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 702)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 731)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 740)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 750)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 751)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 752)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 753)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 754)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 755)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 756)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 757)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 758)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 914)
- SAP_SE — SAP NetWeaver ABAP Server and ABAP Platform (SAP_BASIS 915)

## References

- [CNA](https://me.sap.com/notes/3600846)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.51%
- **EPSS Percentile:** 41.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._