SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3550816 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Patch |
Configurations
Configuration 1 (hide)
|
History
24 Oct 2025, 19:11
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Sap sap Basis
Sap |
|
| References | () https://me.sap.com/notes/3550816 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch | |
| Summary |
|
|
| CPE | cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:* |
14 Jan 2025, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-01-14 01:15
Updated : 2025-10-24 19:11
NVD link : CVE-2025-0063
Mitre link : CVE-2025-0063
CVE.ORG link : CVE-2025-0063
JSON object : View
Products Affected
sap
- sap_basis
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
