VYPR
Medium severity4.3NVD Advisory· Published Apr 8, 2025· Updated Apr 15, 2026

CVE-2025-27437

CVE-2025-27437

Description

SAP NetWeaver AS ABAP has a missing authorization check in its Virus Scanner Interface, letting a low-privilege user access non-sensitive data without permission.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SAP NetWeaver AS ABAP has a missing authorization check in its Virus Scanner Interface, letting a low-privilege user access non-sensitive data without permission.

Vulnerability

The vulnerability lies in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. A missing authorization check allows an authenticated attacker who holds only a non-administrative role to initiate a transaction that should require higher privileges [1]. The root cause is the absence of proper access control enforcement at the point of entry, meaning the system does not verify whether the user has the required authorization to perform the operation.

Exploitation

An attacker must be authenticated as a standard user (not an administrator) to exploit this flaw. No special network access or prior knowledge is needed beyond valid credentials for a low-privileged account. The attacker can trigger the vulnerable transaction remotely, leveraging the missing check to gain access to resources that are ordinarily restricted [1].

Impact

A successful exploitation results in unauthorized access to non-sensitive data. The attacker can view information but cannot modify it, and the vulnerability has no effect on system availability or integrity of data. While the exposed data is classified as non-sensitive, its exposure still violates the principle of least privilege and could aid in further attacks or information gathering [1].

Mitigation

SAP has released a security note as part of its regular Patch Day to address this issue [1]. All customers running affected versions of SAP NetWeaver Application Server ABAP are strongly advised to apply the provided patch promptly. No workarounds have been published, so updating is the only recommended mitigation.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.