CVE-2025-0067 Information
Jan 15, 2025
cve
Description
Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java an attacker with standard user role can create JCo connection entries which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality integrity and availability of the application.
Reference
https://me.sap.com/notes/3540108 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday
Share on: