5

CVE-2025-42968

Missing Authorization check in SAP NetWeaver (RFC enabled function module)

SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPNetweaver Version700
SAPNetweaver Version701
SAPNetweaver Version702
SAPNetweaver Version710
SAPNetweaver Version731
SAPNetweaver Version740
SAPNetweaver Version750
SAPNetweaver Version751
SAPNetweaver Version752
SAPNetweaver Version753
SAPNetweaver Version754
SAPNetweaver Version755
SAPNetweaver Version756
SAPNetweaver Version757
SAPNetweaver Version758
SAPNetweaver Version816
SAPNetweaver Version914
SAPNetweaver Version916
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.364
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
cna@sap.com 5 3.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.