CVE-2025-42918

Published Sep 9, 2025

Last updated 10 months ago

Overview

Description
SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability
Source
cna@sap.com
NVD status
Analyzed
Products
sap_basis

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

cna@sap.com
CWE-862

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.