Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-23186


In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.


Published

2025-04-08T08:15:15.133

Last Modified

2025-04-08T18:13:53.347

Status

Awaiting Analysis

Source

[email protected]

Severity

CVSSv3.1: 8.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products

-


References