Impact
A missing authorization check in SAP NetWeaver and ABAP Platform allows an authenticated attacker to gain unauthorized access to sensitive system configuration information. This breach could expose security‑relevant settings and internal details, presenting a low confidentiality impact while integrity and availability remain unchanged.
Affected Systems
The vulnerability impacts SAP NetWeaver and the ABAP Platform, with no specific version information provided. All installations of these products that have not applied the relevant SAP update are susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium overall severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication, and no publicly documented exploits exist. Consequently, the risk is moderate, underscoring the importance of validating that proper authorization controls are enforced.
OpenCVE Enrichment