Authorization Bypass in SAP NetWeaver
CVE-2025-31331

4.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 April 2025

Summary

SAP NetWeaver is affected by a vulnerability that allows an attacker to circumvent authorization checks, providing unauthorized access to sensitive portions of ABAP code. This occurs after the attacker gains entry into the ABAP system, where they can execute specific transactions that reveal critical system code without the necessary validation. Such exploitation threatens the confidentiality of the system's internal operations and sensitive information.

Affected Version(s)

SAP NetWeaver SAP_ABA 700

SAP NetWeaver 701

SAP NetWeaver 702

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.