CVE-2025-23187: SAP SE SAP NetWeaver And Abap Platform Sdccn
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.
Affected products
- SAP SE SAP NetWeaver And Abap Platform Sdccn
Published 2025-02-11. Last modified 2026-06-17.