CVE-2025-27437
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 8, 2025
CWE ID 862
Summary
CVE-2025-27437 is a vulnerability affecting the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. This issue involves a missing authorization check, enabling a non-administrative user to initiate a transaction unauthorizedly. While they cannot modify sensitive data, they can access non-sensitive data without further authorization, posing a potential security risk. This vulnerability does not impact system availability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sap Netweaver Application Server Abap
Affected Vendors
- SAP SE