Missing Authorization Check in SAP NetWeaver Application Server Java
CVE-2025-0067
Currently unrated
Summary
This vulnerability in the SAP NetWeaver Application Server Java arises from a missing authorization check on service endpoints, which allows an attacker with a standard user role to create JCo connection entries. These entries facilitate remote function calls to and from the application server, potentially jeopardizing the confidentiality, integrity, and availability of the application by enabling unauthorized access.
References
Timeline
Vulnerability published