CVE-2025-0068: Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0068?
CVE-2025-0068 has a low severity as it does not impact the integrity or availability of the application.
How do I fix CVE-2025-0068?
Fixing CVE-2025-0068 involves applying the latest security patch provided by SAP for the NetWeaver Application Server ABAP.
What type of vulnerability is CVE-2025-0068?
CVE-2025-0068 is an authorization vulnerability due to obsolete functionality in SAP NetWeaver Application Server ABAP.
Who is affected by CVE-2025-0068?
Organizations using the SAP NetWeaver Application Server ABAP are affected by CVE-2025-0068.
Can an attacker exploit CVE-2025-0068?
Yes, an authenticated attacker can exploit CVE-2025-0068 to access restricted information.