Action and evidence
Operational decision
- Action type
- Deploy Patch
- Platform
- SAP
- Restart
- unknown
- Vendor signal
- Critical; CVSS 9.9
Why this urgency
- Fix Available
- Routine Review
Evidence signals kept separate
- CISA KEV
- Unknown
- Confirmed exploitation
- Not Stated
- Vendor exploitability
- Not stated in the reviewed source
- Maximum CVSS
- 9.9 (CVSS 3.1, CVE-2025-0070)
- Maximum EPSS
- Not loaded for this patch record
BlackTree recommends the normal approved patch window. No accepted exploitation or emergency signal currently justifies an out-of-band change by itself.
BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.
Environment override questions
- Is SAP NetWeaver Application Server for ABAP and ABAP Platform, Versions – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 7.97, 8.04, 9.12, 9.13, 9.14 exposed to untrusted networks or content?
- Does this update affect an identity, management, backup or other control-plane system?
- Are compensating controls tested and monitored until the selected patch window?
