CVE Vulnerabilities

CVE-2025-42936

Incorrect Privilege Assignment

Published: Aug 12, 2025 | Modified: Oct 23, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the confidentiality and integrity of the application, there is no impact on availability.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Sap_basis Sap 700 (including) 700 (including)
Sap_basis Sap 701 (including) 701 (including)
Sap_basis Sap 702 (including) 702 (including)
Sap_basis Sap 731 (including) 731 (including)
Sap_basis Sap 740 (including) 740 (including)
Sap_basis Sap 750 (including) 750 (including)
Sap_basis Sap 751 (including) 751 (including)
Sap_basis Sap 752 (including) 752 (including)
Sap_basis Sap 753 (including) 753 (including)
Sap_basis Sap 754 (including) 754 (including)
Sap_basis Sap 755 (including) 755 (including)
Sap_basis Sap 756 (including) 756 (including)
Sap_basis Sap 757 (including) 757 (including)
Sap_basis Sap 758 (including) 758 (including)
Sap_basis Sap 816 (including) 816 (including)

Potential Mitigations

References