CVE-2025-31331

MEDIUM

SAP NetWeaver - Authenticated Incorrect Authorization via ABAP Transaction

Title source: llm
STIX 2.1

Description

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (15)
SAP_SE/SAP NetWeaver 701
SAP_SE/SAP NetWeaver 702
SAP_SE/SAP NetWeaver 731
SAP_SE/SAP NetWeaver 740
SAP_SE/SAP NetWeaver 750
SAP_SE/SAP NetWeaver 751
SAP_SE/SAP NetWeaver 752
SAP_SE/SAP NetWeaver 75C
SAP_SE/SAP NetWeaver 75D
SAP_SE/SAP NetWeaver 75E
... and 5 more
Published Apr 08, 2025
Tracked Since Feb 18, 2026