Unauthorized Access Vulnerability in SAP ABAP Platform by SAP
CVE-2025-24872
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 February 2025
What is CVE-2025-24872?
The ABAP Build Framework in SAP ABAP Platform is susceptible to an issue that enables an authenticated attacker to gain unauthorized access to specific transactions. By leveraging the add-on build functionality within the framework, an attacker can invoke certain transactions and inspect their details. Although this vulnerability poses a risk to confidentiality, it does not compromise the integrity or availability of the application.
Affected Version(s)
SAP ABAP Platform (ABAP Build Framework) SAP_BASIS 750
SAP ABAP Platform (ABAP Build Framework) SAP_BASIS 751
SAP ABAP Platform (ABAP Build Framework) SAP_BASIS 752