Impact
SAP ABAP Development Tools lacks necessary authorization checks for certain functions, allowing a user with low privileges to perform unauthorized database operations on SAP NetWeaver AS ABAP. This flaw can enable the attacker to read confidential data, modify application data, and disrupt service for legitimate users, impacting confidentiality, integrity, and availability. The weakness is classified as CWE-862, an authorization issue.
Affected Systems
The vulnerability applies to SAP SE’s SAP ABAP Developer Tools, which is part of the SAP NetWeaver AS ABAP environment. No specific version information is provided, so all installations of SAP ABAP Developer Tools that expose the affected functionality are potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation yet. The likely attack vector is local: an attacker must first obtain a low‑privilege account on the system and then use the developer tools to trigger the unchecked database operations. Because low‑privilege access is relatively easy to acquire through social engineering or existing permissions, the risk of successful exploitation remains significant.
OpenCVE Enrichment