CVE-2025-23190: SAP SE SAP NetWeaver And Abap Platform St-Pi

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system.

Affected products

  • SAP SE SAP NetWeaver And Abap Platform St-Pi

Published 2025-02-11. Last modified 2026-06-17.