Advisory
A note with CVSS 7.5 for component BC-IAM-SSO-CCL was released by SAP on 11.11.2025. The correction/advisory 3633049 was described with "[CVE-2025-42940] Memory Corruption vulnerability in SAP CommonCryptoLib" and affects the system type ABAP Java HANA platform.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is memory corruption within ABAP Java HANA platform.
Risk specification
SAP CommonCryptoLib allows an unauthenticated attacker to send a crafted request that triggers a memory corruption error in the library, resulting in an application crash.Solution
The issue has been resolved through improved boundary checks in SAP CommonCryptoLib.
- 5.3 [CVE-2025-42902] Memory Corruption vulnerability in SAP Netweaver AS ABAP and ABAP Platform
- 4.9 [CVE-2024-33008] Memory Corruption vulnerability in SAP Replication Server
- 4.1 [CVE-2025-30015] Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)
- 4.0 [CVE-2025-42971] Memory Corruption vulnerability in SAPCAR
