CVE-2025-42958: Missing Authentication check in SAP NetWeaver
Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42958?
CVE-2025-42958 has been rated as high severity due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-42958?
To mitigate CVE-2025-42958, ensure that proper authentication checks are implemented in the SAP NetWeaver application.
Who is affected by CVE-2025-42958?
CVE-2025-42958 affects users of the SAP NetWeaver application running on IBM i-series.
What kind of sensitive information can be exposed due to CVE-2025-42958?
CVE-2025-42958 can expose data that includes administrative settings, configuration files, and other sensitive application data.
Can CVE-2025-42958 lead to data manipulation?
Yes, CVE-2025-42958 allows unauthorized users to read, modify, or delete sensitive information.