The SAP NetWeaver Application Server for ABAP does not enable an administrator to assign distinguished authorizations for different user roles, this issue allows authenticated users to access restricted objects in the barcode interface, leading to privilege escalation. This results in a low impact on the confidentiality and integrity of the application, there is no impact on availability.
                
            References
                    | Link | Resource | 
|---|---|
| https://me.sap.com/notes/3602656 | Permissions Required | 
| https://url.sap/sapsecuritypatchday | Patch | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    23 Oct 2025, 12:41
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:816:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:* cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:* | |
| First Time | Sap Sap sap Basis | |
| References | () https://me.sap.com/notes/3602656 - Permissions Required | |
| References | () https://url.sap/sapsecuritypatchday - Patch | 
12 Aug 2025, 14:25
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
12 Aug 2025, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-12 03:15
Updated : 2025-10-23 12:41
NVD link : CVE-2025-42936
Mitre link : CVE-2025-42936
CVE.ORG link : CVE-2025-42936
JSON object : View
Products Affected
                sap
- sap_basis
CWE
                
                    
                        
                        CWE-266
                        
            Incorrect Privilege Assignment
