CVE-2025-42953 Information
Jul 09, 2025
cve
Description
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Reference
https://me.sap.com/notes/3623440 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Related CNNVD
CNNVD-202507-797 (Published: 2025-07-08)
Share on: