VYPR
Medium severity4.3NVD Advisory· Published Jul 8, 2025· Updated Jun 17, 2026

CVE-2025-42986

CVE-2025-42986

Description

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability of the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Range: SAP_BASIS 700
  • SAP/BASISllm-fuzzy11 versions
    (expand)+ 10 more
    • (no CPE)
    • cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.