Medium severity4.3NVD Advisory· Published Jul 8, 2025· Updated Jun 17, 2026
CVE-2025-42986
CVE-2025-42986
Description
Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- Range: SAP_BASIS 700
(expand)+ 10 more
- (no CPE)
- cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdPatch
- me.sap.com/notes/3626440nvdPermissions Required
News mentions
0No linked articles in our index yet.