CVE-2025-42989

CRITICAL

SAP NetWeaver Application Server for ABAP - Authenticated Privilege Escalation via RFC Inbound Processing

Title source: llm
STIX 2.1

Description

RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 9.6
EPSS 0.0023
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (4)
SAP_SE/SAP NetWeaver Application Server for ABAP 7.93
SAP_SE/SAP NetWeaver Application Server for ABAP 9.14
SAP_SE/SAP NetWeaver Application Server for ABAP 9.15
SAP_SE/SAP NetWeaver Application Server for ABAP KERNEL 7.89
Published Jun 10, 2025
Tracked Since Feb 18, 2026