PT-2025-1182 · Sap · Sap Netweaver Application Server Abap
Published
2025-01-14
·
Updated
2025-01-14
·
CVE-2025-0068
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Application Server ABAP (affected versions not specified)
Description
The issue is related to an obsolete functionality in SAP NetWeaver Application Server ABAP that did not perform necessary authorization checks. This allows an authenticated attacker to obtain information that would otherwise be restricted. The issue has no impact on the integrity or availability of the application. It is associated with a lack of authorization, which can be exploited by a remote attacker to disclose protected information.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver Application Server Abap