CVE-2025-0067 Information

Description

Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java an attacker with standard user role can create JCo connection entries which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality integrity and availability of the application.

Reference

https://me.sap.com/notes/3540108 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday

Share on: