CVE-2025-27437: Missing Authorization check in SAP NetWeaver Application Server ABAP (Virus Scan Interface)
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and with no effect on availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27437?
CVE-2025-27437 has been rated with a medium severity level due to its potential impact on unauthorized data access.
How do I fix CVE-2025-27437?
To resolve CVE-2025-27437, ensure that proper authorization checks are implemented in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP.
Who is affected by CVE-2025-27437?
CVE-2025-27437 affects users of the SAP NetWeaver Application Server ABAP who may be utilizing the Virus Scanner Interface.
What type of data is at risk with CVE-2025-27437?
CVE-2025-27437 allows non-administrative users to access non-sensitive data, posing a risk to data exposure.
Can CVE-2025-27437 be exploited remotely?
CVE-2025-27437 requires an authenticated user to exploit the vulnerability, which adds a layer of complexity to remote exploitation.