SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 08 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 08 Apr 2025 07:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality. | |
| Title | Authorization Bypass vulnerability in SAP NetWeaver | |
| Weaknesses | CWE-863 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: sap
Published: 2025-04-08T07:15:23.750Z
Updated: 2025-04-08T13:15:55.752Z
Reserved: 2025-03-27T23:02:06.907Z
Link: CVE-2025-31331
Updated: 2025-04-08T13:15:50.951Z
Status : Awaiting Analysis
Published: 2025-04-08T08:15:17.977
Modified: 2025-04-08T18:13:53.347
Link: CVE-2025-31331
No data.