cbcvebase.
CVE-2025-31331
published 2025-04-08

CVE-2025-31331: SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation…

PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.34%
25.6th percentile
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.

Affected

15 ranges
VendorProductVersion rangeFixed in
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
sap_sesap_netweaver
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.