CVE-2025-23194: SAP SE SAP NetWeaver Enterprise Portal Obn Component

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application.

Affected products

  • SAP SE SAP NetWeaver Enterprise Portal Obn Component

Published 2025-03-11. Last modified 2026-06-17.