RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Jun 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application. | |
Title | Missing Authorization check in SAP NetWeaver Application Server for ABAP | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-06-10T00:12:16.278Z
Updated: 2025-06-11T04:01:27.213Z
Reserved: 2025-04-16T13:25:48.060Z
Link: CVE-2025-42989

Updated: 2025-06-10T14:18:43.858Z

Status : Awaiting Analysis
Published: 2025-06-10T01:15:22.183
Modified: 2025-06-12T16:06:39.330
Link: CVE-2025-42989

No data.