Vulnerability Details CVE-2025-42911
SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and availability of the application
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 8.4%
CVSS Severity
CVSS v3 Score 5.0
Products affected by CVE-2025-42911
-
cpe:2.3:a:sap:sap_basis:700
-
cpe:2.3:a:sap:sap_basis:701
-
cpe:2.3:a:sap:sap_basis:702
-
cpe:2.3:a:sap:sap_basis:731
-
cpe:2.3:a:sap:sap_basis:740
-
cpe:2.3:a:sap:sap_basis:750
-
cpe:2.3:a:sap:sap_basis:751
-
cpe:2.3:a:sap:sap_basis:752
-
cpe:2.3:a:sap:sap_basis:753
-
cpe:2.3:a:sap:sap_basis:754
-
cpe:2.3:a:sap:sap_basis:755
-
cpe:2.3:a:sap:sap_basis:756
-
cpe:2.3:a:sap:sap_basis:757
-
cpe:2.3:a:sap:sap_basis:758
-
cpe:2.3:a:sap:sap_basis:816