CVE-2025-42911: SAP Basis

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP NetWeaver (Service Data Download) allows an authenticated user to call a remote-enabled function module, which could grant access to information about the SAP system and operating system. This leads to a low impact on confidentiality, with no effect on the integrity and availability of the application

Affected products

  • SAP SAP Basis: version 700 only; version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; …

Published 2025-09-09. Last modified 2026-06-17.