First published: Tue Apr 08 2025(Updated: )
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and with no effect on availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27437 has been rated with a medium severity level due to its potential impact on unauthorized data access.
To resolve CVE-2025-27437, ensure that proper authorization checks are implemented in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP.
CVE-2025-27437 affects users of the SAP NetWeaver Application Server ABAP who may be utilizing the Virus Scanner Interface.
CVE-2025-27437 allows non-administrative users to access non-sensitive data, posing a risk to data exposure.
CVE-2025-27437 requires an authenticated user to exploit the vulnerability, which adds a layer of complexity to remote exploitation.