#VU103913 Missing authorization in SAP NetWeaver AS ABAP - CVE-2025-23189
Published: February 12, 2025
SAP NetWeaver AS ABAP
SAP
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to missing authorization checks in an RFC enabled function module in transaction SDCCN. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application.