RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application. | |
| Title | Missing Authorization check in SAP NetWeaver Application Server for ABAP | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-06-10T00:12:16.278Z
Updated: 2025-06-11T04:01:27.213Z
Reserved: 2025-04-16T13:25:48.060Z
Link: CVE-2025-42989
Updated: 2025-06-10T14:18:43.858Z
Status : Awaiting Analysis
Published: 2025-06-10T01:15:22.183
Modified: 2025-06-12T16:06:39.330
Link: CVE-2025-42989
No data.