CVE-2025-31331 MEDIUM

CVE-2025-31331: Authorization Bypass vulnerability in SAP NetWeaver

Vendor Sap_Se
Product SAP NetWeaver
Weakness CWE-863 · Incorrect authorization
Published April 8, 2025
Last update April 8, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.

Key dates

02Disclosure timeline

April 8, 2025 CVE published
April 8, 2025 Record updated