Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 12 Aug 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap abap Platform |
|
Vendors & Products |
Sap
Sap abap Platform |
Tue, 12 Aug 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected. | |
Title | Missing Authorization check in ABAP Platform | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-08-12T02:08:28.405Z
Updated: 2025-08-13T20:20:21.800Z
Reserved: 2025-04-16T13:25:37.188Z
Link: CVE-2025-42949

Updated: 2025-08-12T13:30:48.442Z

Status : Awaiting Analysis
Published: 2025-08-12T03:15:27.657
Modified: 2025-08-12T14:25:33.177
Link: CVE-2025-42949

No data.