Missing Authorization Check in SAP NetWeaver Application Server Java
CVE-2025-0067

Currently unrated

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 January 2025

Summary

This vulnerability in the SAP NetWeaver Application Server Java arises from a missing authorization check on service endpoints, which allows an attacker with a standard user role to create JCo connection entries. These entries facilitate remote function calls to and from the application server, potentially jeopardizing the confidentiality, integrity, and availability of the application by enabling unauthorized access.

References

Timeline

  • Vulnerability published

.