SAP NetWeaver Missing Authorization Check in RFC Function Module Vulnerability in Transaction SDCCN

Vulnerability

A vulnerability exists in an RFC-enabled function module within the SAP NetWeaver platform, specifically in transaction SDCCN. The issue arises from a missing authorization check, allowing an unauthenticated attacker to generate technical metadata. This vulnerability has a low impact on integrity, with no effects on confidentiality or availability.

Impact

Exploitation of this vulnerability could lead to unauthorized generation of technical metadata, potentially allowing for further attacks or exploitation of other vulnerabilities.

Remediation

Users are advised to review the SAP Security Notes related to this vulnerability and implement the recommended patches. SAP Security Notes can be accessed through the SAP for Me platform.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.