SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability
History

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap application Server
Sap background Processing
Sap netweaver
Sap netweaver Abap
Vendors & Products Sap
Sap application Server
Sap background Processing
Sap netweaver
Sap netweaver Abap

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 02:15:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability
Title Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-09-09T02:09:18.915Z

Updated: 2025-09-09T13:41:50.007Z

Reserved: 2025-04-16T13:25:30.253Z

Link: CVE-2025-42918

cve-icon Vulnrichment

Updated: 2025-09-09T13:41:44.906Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T02:15:40.110

Modified: 2025-09-09T16:28:43.660

Link: CVE-2025-42918

cve-icon Redhat

No data.