CVE-2025-0063: SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0063?
CVE-2025-0063 has a high severity rating due to the potential for complete compromise of data confidentiality.
How do I fix CVE-2025-0063?
To fix CVE-2025-0063, ensure that authorization checks are properly implemented for RFC function module executions.
Who is affected by CVE-2025-0063?
CVE-2025-0063 affects users of SAP NetWeaver AS ABAP and SAP ABAP Platform.
Can CVE-2025-0063 be exploited remotely?
Yes, CVE-2025-0063 can be exploited remotely by an attacker with basic user privileges.
What could an attacker gain from exploiting CVE-2025-0063?
An attacker could gain control over data in the Informix database, leading to a complete compromise of confidentiality.