Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist this attacker to plan subsequent attacks. As a result, this vulnerability has a low impact on confidentiality, with no impact on the integrity or availability of the application.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap application Server
Sap netweaver
Sap netweaver Abap
Sap netweaver Abap Application Server
Sap netweaver Application Server
Sap netweaver Application Server For Abap
Vendors & Products Sap
Sap application Server
Sap netweaver
Sap netweaver Abap
Sap netweaver Abap Application Server
Sap netweaver Application Server
Sap netweaver Application Server For Abap

Tue, 11 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist this attacker to plan subsequent attacks. As a result, this vulnerability has a low impact on confidentiality, with no impact on the integrity or availability of the application.
Title Missing Authorization check in SAP NetWeaver Application Server for ABAP
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-11-11T00:13:33.144Z

Reserved: 2025-04-16T13:25:19.826Z

Link: CVE-2025-42882

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T01:15:36.557

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-42882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-12T12:47:49Z