The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the confidentiality and integrity of the application, there is no impact on availability.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3602656 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Patch |
Configurations
Configuration 1 (hide)
|
History
23 Oct 2025, 12:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://me.sap.com/notes/3602656 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch | |
| First Time |
Sap
Sap sap Basis |
|
| CPE | cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:816:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:* |
12 Aug 2025, 14:25
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
12 Aug 2025, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-12 03:15
Updated : 2025-10-23 12:41
NVD link : CVE-2025-42936
Mitre link : CVE-2025-42936
CVE.ORG link : CVE-2025-42936
JSON object : View
Products Affected
sap
- sap_basis
CWE
CWE-266
Incorrect Privilege Assignment
