The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the confidentiality and integrity of the application, there is no impact on availability.
Metrics
Affected Vendors & Products
References
History
Tue, 12 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap netweaver Application Server For Abap |
|
Vendors & Products |
Sap
Sap netweaver Application Server For Abap |
Tue, 12 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the confidentiality and integrity of the application, there is no impact on availability. | |
Title | Missing Authorization check in SAP NetWeaver Application Server for ABAP | |
Weaknesses | CWE-266 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-08-12T02:05:19.690Z
Updated: 2025-08-13T15:03:51.218Z
Reserved: 2025-04-16T13:25:34.582Z
Link: CVE-2025-42936

Updated: 2025-08-12T14:05:34.056Z

Status : Awaiting Analysis
Published: 2025-08-12T03:15:26.477
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-42936

No data.