Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected.
References
Configurations
No configuration.
History
12 Aug 2025, 14:25
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
12 Aug 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-12 03:15
Updated : 2025-08-12 14:25
NVD link : CVE-2025-42949
Mitre link : CVE-2025-42949
CVE.ORG link : CVE-2025-42949
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization