Authorization Bypass Vulnerability in SAP Software
CVE-2025-42974
4.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 8 July 2025
What is CVE-2025-42974?
An authorization bypass issue has been identified in SAP software, allowing authenticated users without administrative privileges to invoke remote-enabled function modules. This vulnerability could potentially grant access to sensitive information that should be restricted to privileged users, posing a risk to confidentiality. While the integrity and availability of the systems remain intact, organizations should assess and mitigate the risks associated with this flaw.
Affected Version(s)
SAP NetWeaver and ABAP Platform (SDCCN) ST-PI 2008_1_700
SAP NetWeaver and ABAP Platform (SDCCN) 2008_1_710
SAP NetWeaver and ABAP Platform (SDCCN) 740