CVE-2025-27437

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 862

Summary

CVE-2025-27437 is a vulnerability affecting the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. This issue involves a missing authorization check, enabling a non-administrative user to initiate a transaction unauthorizedly. While they cannot modify sensitive data, they can access non-sensitive data without further authorization, posing a potential security risk. This vulnerability does not impact system availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sap Netweaver Application Server Abap

Affected Vendors

  • SAP SE