Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system. | |
Title | Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI) | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-02-11T00:35:03.340Z
Updated: 2025-02-11T16:01:38.164Z
Reserved: 2025-01-13T11:13:59.547Z
Link: CVE-2025-23190

Updated: 2025-02-11T16:01:32.626Z

Status : Received
Published: 2025-02-11T01:15:10.413
Modified: 2025-02-11T01:15:10.413
Link: CVE-2025-23190

No data.