CVE-2025-23194
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
11/03/2025
Last modified:
15/04/2026
Description
SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



