Action and evidence
Operational decision
- Action type
- Deploy Patch
- Platform
- SAP
- Restart
- unknown
- Vendor signal
- Critical; CVSS 9.9
Why this urgency
- Fix Available
- Routine Review
Evidence signals kept separate
- CISA KEV
- Unknown
- Confirmed exploitation
- Not Stated
- Vendor exploitability
- Not stated in the reviewed source
- Maximum CVSS
- 9.9 (CVSS 3.1, CVE-2025-0066)
- Maximum EPSS
- Not loaded for this patch record
BlackTree recommends the normal approved patch window. No accepted exploitation or emergency signal currently justifies an out-of-band change by itself.
BlackTree urgency is an operational review window. It does not replace vendor severity or CVSS.
Environment override questions
- Is SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914 exposed to untrusted networks or content?
- Does this update affect an identity, management, backup or other control-plane system?
- Are compensating controls tested and monitored until the selected patch window?
