CVE-2025-42958
9.1SAP · SAP NetWeaver
A missing authentication check in SAP NetWeaver on IBM i-series allows highly privileged users to execute unauthorized actions, including reading, modifying, or deleting sensitive information.
Executive summary
A critical authentication bypass vulnerability in SAP NetWeaver on IBM i-series systems allows high-privileged users to perform unauthorized operations, risking full system compromise.
Vulnerability
This vulnerability (CWE-250) involves a missing authentication check that allows users with high privileges to perform unauthorized actions beyond their scope. The CVSS vector PR:H indicates that an attacker must already possess high-level administrative access to exploit this flaw.
Business impact
While the vulnerability requires high privileges, the ability to read, modify, or delete sensitive information represents a total impact on data confidentiality, integrity, and availability. With a CVSS score of 9.1, this represents a significant risk for enterprise environments where SAP NetWeaver manages critical business processes.
Remediation
Immediate Action: Review the official SAP Security Patch Day notes (Note 3627373) and apply the necessary kernel updates or configuration changes provided by SAP.
Proactive Monitoring: Review audit logs for suspicious activity originating from highly privileged accounts that deviate from established administrative workflows.
Compensating Controls: Implement strict identity and access management (IAM) controls to limit the number of users with high privileges and ensure that access is granted on a least-privilege basis.
Exploitation status
Public Exploit Available: Unknown (No weaponized exploit or curated public PoC confirmed in available data).
Analyst recommendation
Organizations utilizing SAP NetWeaver on IBM i-series should treat this with high urgency. Consult the referenced SAP security notes to identify the specific patch requirements for your kernel version and apply them during the next maintenance window.