CVE-2025-42949
BaseFortify
Publication date: 2025-08-12
Last updated on: 2025-08-12
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | abap_platform | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is caused by a missing authorization check in the ABAP Platform. An authenticated user with elevated privileges can bypass authorization restrictions for common transactions by using the SQL Console. This allows the attacker to access and read database table contents without proper authorization, compromising data confidentiality. The system's integrity and availability are not affected.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive data stored in database tables, resulting in a significant compromise of data confidentiality. However, it does not impact the integrity or availability of the system.