CVE-2025-42875 MEDIUM

CVE-2025-42875: Missing Authentication check in SAP NetWeaver Internet Communication Framework

Vendor Sap_Se
Product SAP NetWeaver Internet Communication Framework
Weakness CWE-306 · Missing auth
Published December 9, 2025
Last update December 9, 2025

CVSS base score

6.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application.

Key dates

02Disclosure timeline

December 9, 2025 CVE published
December 9, 2025 Record updated