CVE-2025-42953HIGH 8.1EPSS p33.1%
CVE-2025-42953CVE-2025-42953
Description
SAP Netweaver System Configuration does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This could completely compromise the integrity and availability with no impact on confidentiality of the system.
Scoring
| CVSS 3.1 | 8.1 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| EPSS | 0.41% probability of exploitation · percentile 33.1% · 2026-06-19T12:03:05Z |
| Published | 2025-07-08 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Authorizationcwe-862 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.