SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.
History

Tue, 14 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.
Title SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-01-14T00:09:28.885Z

Updated: 2025-01-14T14:51:11.362Z

Reserved: 2024-12-05T21:53:06.796Z

Link: CVE-2025-0063

cve-icon Vulnrichment

Updated: 2025-01-14T14:51:07.161Z

cve-icon NVD

Status : Received

Published: 2025-01-14T01:15:16.633

Modified: 2025-01-14T01:15:16.633

Link: CVE-2025-0063

cve-icon Redhat

No data.