SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability
History

Thu, 23 Oct 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap sap Basis
CPEs cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:816:*:*:*:*:*:*:*
Vendors & Products Sap sap Basis

Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap application Server
Sap background Processing
Sap netweaver
Sap netweaver Abap
Vendors & Products Sap
Sap application Server
Sap background Processing
Sap netweaver
Sap netweaver Abap

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 02:15:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability
Title Missing Authorization check in SAP NetWeaver Application Server for ABAP (Background Processing)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-09-09T02:09:18.915Z

Updated: 2025-09-09T13:41:50.007Z

Reserved: 2025-04-16T13:25:30.253Z

Link: CVE-2025-42918

cve-icon Vulnrichment

Updated: 2025-09-09T13:41:44.906Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-09T02:15:40.110

Modified: 2025-10-23T12:44:38.700

Link: CVE-2025-42918

cve-icon Redhat

No data.