CVE-2025-42936: Missing Authorization check in SAP NetWeaver Application Server for ABAP
The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the confidentiality and integrity of the application, there is no impact on availability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42936?
CVE-2025-42936 is classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-42936?
To fix CVE-2025-42936, ensure that user roles are properly configured with distinct authorizations to restrict access to sensitive objects in the barcode interface.
What type of access does CVE-2025-42936 expose?
CVE-2025-42936 allows authenticated users to access restricted objects, leading to unauthorized privilege escalation.
Who is affected by CVE-2025-42936?
CVE-2025-42936 affects users of the SAP NetWeaver Application Server for ABAP, particularly in configurations lacking proper authorization controls.
Is there a workaround for CVE-2025-42936?
A temporary workaround for CVE-2025-42936 includes manually reviewing and adjusting user roles to ensure proper authorization separation until a patch is applied.