The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Sap sap Netweaver |
|
| Vendors & Products |
Sap
Sap netweaver Sap sap Netweaver |
Tue, 09 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SAP Internet Communication Framework does not conduct any authentication checks for features that need user identification allowing an attacker to reuse authorization tokens, violating secure authentication practices causing low impact on Confidentiality, Integrity and Availability of the application. | |
| Title | Missing Authentication check in SAP NetWeaver Internet Communication Framework | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-12-09T02:14:30.399Z
Updated: 2025-12-09T16:02:35.100Z
Reserved: 2025-04-16T13:25:17.023Z
Link: CVE-2025-42875
Updated: 2025-12-09T14:23:54.432Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:51.667
Modified: 2025-12-09T18:36:53.557
Link: CVE-2025-42875
No data.