Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20341 | SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the application. |
Mon, 27 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver |
|
| CPEs | cpe:2.3:a:sap:netweaver:700:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:701:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:702:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:710:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:731:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:740:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:750:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:751:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:752:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:753:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:754:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:755:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:756:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:757:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:758:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:816:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:914:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver:916:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap netweaver |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the application. | |
| Title | Missing Authorization check in SAP NetWeaver (RFC enabled function module) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-07-08T16:13:36.672Z
Reserved: 2025-04-16T13:25:42.158Z
Link: CVE-2025-42968
Updated: 2025-07-08T14:29:05.128Z
Status : Analyzed
Published: 2025-07-08T01:15:23.950
Modified: 2025-10-27T16:57:45.097
Link: CVE-2025-42968
No data.
OpenCVE Enrichment
No data.
EUVD