SAP ABAP Platform Missing Authorization Check Vulnerability Allowing Unauthorized Database Access

Vulnerability

A vulnerability exists in the SAP ABAP Platform due to a missing authorization check. This flaw allows an authenticated user with elevated privileges to bypass authorization restrictions for common transactions by using the SQL Console. Exploiting this vulnerability could enable access to and reading of database table contents without proper authorization, significantly compromising data confidentiality. However, the system's integrity and availability remain unaffected.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive data in database tables, creating a risk of data leakage or misuse.

Remediation

Users are advised to review and implement the SAP Security Note associated with this vulnerability. This can be done through the SAP for Me platform, specifically during the monthly SAP Security Patch Day.

Added: Aug 12, 2025, 3:42 AM
Updated: Aug 12, 2025, 3:42 AM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
4.4
remediation
8.3
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.