4.3

CVE-2025-42986

Missing Authorization check in SAP NetWeaver and ABAP Platform

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Sap Basis Version 700
SAP ≫ Sap Basis Version 701
SAP ≫ Sap Basis Version 702
SAP ≫ Sap Basis Version 731
SAP ≫ Sap Basis Version 740
SAP ≫ Sap Basis Version 750
SAP ≫ Sap Basis Version 751
SAP ≫ Sap Basis Version 752
SAP ≫ Sap Basis Version 753
SAP ≫ Sap Basis Version 754
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.124
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
SAP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://url.sap/sapsecuritypatchday
Patch
https://me.sap.com/notes/3626440
Permissions Required