CVE-2025-42989
RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
- Base score: 9.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.44%
- Percentile among all scored CVEs: 36
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement85 % - Primary impact
T1068Exploitation for Privilege Escalationprivilege escalation90 % - Secondary impact
T1565.002Transmitted Data Manipulationimpact75 %
AV:N/PR:L/UI:N indica explotación de servicio remoto con credenciales (T1210). CWE-862 (falta de autorización) + CI:H/A:H permiten escalada de privilegios (T1068) e impacto en integridad/disponibilidad (manipulación de datos T1565.002).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
CWEs
- CWE-862
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-42989",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-42989",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-06-11T04:01:27.978618Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@sap.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9.6,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 5.8,
"exploitabilityScore": 3.1
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP_SE",
"product": "SAP NetWeaver Application Server for ABAP",
"versions": [
{
"status": "affected",
"version": "KERNEL 7.89"
},
{
"status": "affected",
"version": "7.93"
},
{
"status": "affected",
"version": "9.14"
},
{
"status": "affected",
"version": "9.15"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-06-10T01:15:22.183",
"references": [
{
"url": "https://me.sap.com/notes/3600840",
"source": "cna@sap.com"
},
{
"url": "https://url.sap/sapsecuritypatchday",
"source": "cna@sap.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@sap.com",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "RFC inbound processing�does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation the attacker could critically impact both integrity and availability of the application."
},
{
"lang": "es",
"value": "El procesamiento entrante de RFC no realiza las comprobaciones de autorización necesarias para un usuario autenticado, lo que resulta en una escalada de privilegios. Si se explota con éxito, el atacante podría afectar gravemente la integridad y la disponibilidad de la aplicación."
}
],
"lastModified": "2026-06-17T09:23:21.040",
"sourceIdentifier": "cna@sap.com"
}