CVE-2025-23193: Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP

Medium (5.3)

Sign up for FREE to recieve instant alerts about this vulnerability!

Description

SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 0.19261 (how common is this exploit)

EPSS Date: 2025-02-11 (when was this score calculated)

Classification

CVE ID: CVE-2025-23193

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

Vendor: SAP_SE

Product: SAP NetWeaver Server ABAP

Timeline