Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability of the application.
2025-07-08T01:15:25.730
2025-10-27T16:55:48.213
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | sap_basis | 700 | Yes |
| Application | sap | sap_basis | 701 | Yes |
| Application | sap | sap_basis | 702 | Yes |
| Application | sap | sap_basis | 731 | Yes |
| Application | sap | sap_basis | 740 | Yes |
| Application | sap | sap_basis | 750 | Yes |
| Application | sap | sap_basis | 751 | Yes |
| Application | sap | sap_basis | 752 | Yes |
| Application | sap | sap_basis | 753 | Yes |
| Application | sap | sap_basis | 754 | Yes |