Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-42949

Опубликовано: 12 авг. 2025
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected.

EPSS

Процентиль: 8%
0.0003
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.9
github
6 месяцев назад

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected.

CVSS3: 4.9
fstec
6 месяцев назад

Уязвимость программной интеграционной платформы SAP NetWeaver ABAP, связанная с отсутствием авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 8%
0.0003
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-862