CVE-2025-42986: SAP Basis
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability of the application.
Affected products
- SAP SAP Basis: version 700 only; version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; …
Published 2025-07-08. Last modified 2026-06-17.