SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Apr 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality. | |
Title | Authorization Bypass vulnerability in SAP NetWeaver | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-04-08T13:15:55.752Z
Reserved: 2025-03-27T23:02:06.907Z
Link: CVE-2025-31331

Updated: 2025-04-08T13:15:50.951Z

Status : Awaiting Analysis
Published: 2025-04-08T08:15:17.977
Modified: 2025-04-08T18:13:53.347
Link: CVE-2025-31331

No data.

No data.