Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-27195 Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 09 Sep 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap netweaver
Sap sap Netweaver
Vendors & Products Sap
Sap netweaver
Sap sap Netweaver

Tue, 09 Sep 2025 02:15:00 +0000

Type Values Removed Values Added
Description Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.
Title Missing Authentication check in SAP NetWeaver
Weaknesses CWE-250
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-09-10T03:55:59.300Z

Reserved: 2025-04-16T13:25:39.583Z

Link: CVE-2025-42958

cve-icon Vulnrichment

Updated: 2025-09-09T19:23:40.452Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T02:15:42.363

Modified: 2025-09-09T16:28:43.660

Link: CVE-2025-42958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-09T21:31:45Z