Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly sensitive information. It could also have a high impact on the integrity and availability of the application.
History

Tue, 11 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description Due to missing authorization check, SAP NetWeaver (ABAP Class Builder) allows an attacker to gain higher access levels than they should have, resulting in escalation of privileges. On successful exploitation, this could result in disclosure of highly sensitive information. It could also have a high impact on the integrity and availability of the application.
Title Missing Authorization check in SAP NetWeaver (ABAP Class Builder)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-03-11T00:37:11.712Z

Updated: 2025-03-12T04:00:29.868Z

Reserved: 2025-02-12T21:05:31.736Z

Link: CVE-2025-26661

cve-icon Vulnrichment

Updated: 2025-03-11T02:08:16.431Z

cve-icon NVD

Status : Received

Published: 2025-03-11T01:15:35.993

Modified: 2025-03-11T01:15:35.993

Link: CVE-2025-26661

cve-icon Redhat

No data.