CVE-2025-31331: SAP SE SAP NetWeaver

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.

Affected products

  • SAP SE SAP NetWeaver: version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; version 751 only; …

Published 2025-04-08. Last modified 2026-06-17.