Missing Authorization Check in SAP Functions
CVE-2025-23190
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 February 2025
What is CVE-2025-23190?
A missing authorization check in SAP's remote-enabled function modules allows authenticated attackers to access sensitive data without proper authorization. While attackers cannot modify any data or disrupt system availability, the potential exposure of confidential information poses significant security risks. It is essential for users to update their systems in accordance with the latest security patches provided by SAP to mitigate this vulnerability.
Affected Version(s)
SAP NetWeaver and ABAP platform (ST-PI) ST-PI 2008_1_700
SAP NetWeaver and ABAP platform (ST-PI) ST-PI 2008_1_710
SAP NetWeaver and ABAP platform (ST-PI) ST-PI 740