Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Jul 8, 2025
Missing Authorization check in SAP NetWeaver (RFC enabled function module)
CVE-2025-42968
Description
SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the application.
Affected products
1- Range: SAP_BW 700
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.