PT-2025-32609 · Sap · Abap Platform

Published

2025-08-11

·

Updated

2025-08-12

·

CVE-2025-42949

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ABAP Platform (affected versions not specified)
Description: A missing authorization check in the ABAP Platform allows an authenticated user with elevated privileges to bypass authorization restrictions for common transactions using the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, compromising data confidentiality. The integrity and availability of the system are not affected.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-16306
CVE-2025-42949

Affected Products

Abap Platform