SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application.
History

Tue, 11 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application.
Title Missing Authentication check in SAP NetWeaver Enterprise Portal (OBN component)
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-03-11T02:13:53.935Z

Reserved: 2025-01-13T11:13:59.547Z

Link: CVE-2025-23194

cve-icon Vulnrichment

Updated: 2025-03-11T02:13:47.408Z

cve-icon NVD

Status : Received

Published: 2025-03-11T01:15:34.630

Modified: 2025-03-11T01:15:34.630

Link: CVE-2025-23194

cve-icon Redhat

No data.