Vulnerability Details CVE-2025-42968
SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.9%
CVSS Severity
CVSS v3 Score 5.0
Products affected by CVE-2025-42968
-
cpe:2.3:a:sap:netweaver:700
-
cpe:2.3:a:sap:netweaver:701
-
cpe:2.3:a:sap:netweaver:702
-
cpe:2.3:a:sap:netweaver:710
-
cpe:2.3:a:sap:netweaver:731
-
cpe:2.3:a:sap:netweaver:740
-
cpe:2.3:a:sap:netweaver:750
-
cpe:2.3:a:sap:netweaver:751
-
cpe:2.3:a:sap:netweaver:752
-
cpe:2.3:a:sap:netweaver:753
-
cpe:2.3:a:sap:netweaver:754
-
cpe:2.3:a:sap:netweaver:755
-
cpe:2.3:a:sap:netweaver:756
-
cpe:2.3:a:sap:netweaver:757
-
cpe:2.3:a:sap:netweaver:758
-
cpe:2.3:a:sap:netweaver:816
-
cpe:2.3:a:sap:netweaver:914
-
cpe:2.3:a:sap:netweaver:916