Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist this attacker to plan subsequent attacks. As a result, this vulnerability has a low impact on confidentiality, with no impact on the integrity or availability of the application.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap application Server Sap netweaver Sap netweaver Abap Sap netweaver Abap Application Server Sap netweaver Application Server Sap netweaver Application Server For Abap |
|
| Vendors & Products |
Sap
Sap application Server Sap netweaver Sap netweaver Abap Sap netweaver Abap Application Server Sap netweaver Application Server Sap netweaver Application Server For Abap |
Tue, 11 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic privileges could execute a specific function module in ABAP to retrieve restricted technical information from the system. This disclosure of environment details of the system could further assist this attacker to plan subsequent attacks. As a result, this vulnerability has a low impact on confidentiality, with no impact on the integrity or availability of the application. | |
| Title | Missing Authorization check in SAP NetWeaver Application Server for ABAP | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-11-11T00:13:33.144Z
Reserved: 2025-04-16T13:25:19.826Z
Link: CVE-2025-42882
No data.
Status : Awaiting Analysis
Published: 2025-11-11T01:15:36.557
Modified: 2025-11-12T16:19:59.103
Link: CVE-2025-42882
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:47:49Z