First published: Tue Feb 11 2025(Updated: )
Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | ||
SAP ABAP Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23187 has a low impact on integrity but does not affect confidentiality or availability.
To mitigate CVE-2025-23187, ensure proper authorization checks are implemented in the relevant RFC-enabled function modules.
CVE-2025-23187 affects SAP NetWeaver and SAP ABAP Platform.
CVE-2025-23187 allows an unauthenticated attacker to generate technical meta-data due to missing authorization checks.
The vulnerability exists in an RFC-enabled function module within transaction SDCCN.