SAP NetWeaver Service Data Download Vulnerability
CVE-2025-42911

5MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 September 2025

What is CVE-2025-42911?

The SAP NetWeaver Service Data Download feature contains a vulnerability that allows an authenticated user to execute a remote-enabled function module. This may lead to unauthorized access to sensitive information regarding the SAP system and its operating environment. While the impact on confidentiality is low, it raises concerns over the potential for exposed data, highlighting the importance of monitoring user access and securing system functionalities.

Affected Version(s)

SAP NetWeaver (Service Data Download) SAP_BASIS 700

SAP NetWeaver (Service Data Download) SAP_BASIS 701

SAP NetWeaver (Service Data Download) SAP_BASIS 702

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.