CVE-2025-23186: Mixed Dynamic RFC Destination vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23186?
CVE-2025-23186 has been classified as a critical vulnerability due to the risk of credential exposure.
How do I fix CVE-2025-23186?
To fix CVE-2025-23186, ensure you apply the latest security patches provided by SAP for the NetWeaver Application Server ABAP.
What can an attacker do with CVE-2025-23186?
An attacker exploiting CVE-2025-23186 can craft Remote Function Call requests to access restricted destinations and expose sensitive credentials.
Who is affected by CVE-2025-23186?
CVE-2025-23186 affects users of the SAP NetWeaver Application Server ABAP who have not implemented appropriate security measures.
When was CVE-2025-23186 reported?
CVE-2025-23186 was reported recently, highlighting an important vulnerability in SAP's security framework.