CVE-2025-23187: SAP SE SAP NetWeaver And Abap Platform Sdccn

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.

Affected products

  • SAP SE SAP NetWeaver And Abap Platform Sdccn

Published 2025-02-11. Last modified 2026-06-17.