VYPR
Medium severity5.0NVD Advisory· Published Sep 9, 2025· Updated Jun 17, 2026

CVE-2025-42911

CVE-2025-42911

Description

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and availability of the application

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17
  • SAP/BASIS15 versions
    cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:816:*:*:*:*:*:*:*
  • SAP/Netweaverllm-fuzzy
  • Range: SAP_BASIS 700

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.