VulnerabilityAnalyzed
CVE-2025-42918
SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters.
MEDIUM 4.3EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
SAP NetWeaver Application Server for ABAP allows authenticated users with access to background processing to gain unauthorized read access to profile parameters. This results in a low impact on confidentiality, with no impact on integrity or availability
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- sap/sap basis
- Source
- cna@sap.com
References
- https://me.sap.com/notes/3623504Permissions Required
- https://url.sap/sapsecuritypatchdayPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.