First published: Tue Feb 11 2025(Updated: )
SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server for ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23193 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2025-23193, ensure that you apply the latest security patches released by SAP for the NetWeaver Application Server ABAP.
CVE-2025-23193 affects users of SAP NetWeaver Application Server ABAP without proper security configurations.
No, CVE-2025-23193 does not allow for data modification, but it can lead to information disclosure.
To mitigate CVE-2025-23193, review your user access controls and monitor network traffic for unusual activity.