CVE-2025-31331
Last modified
CVE-2025-31331 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
SAP NetWeaver allows an attacker to bypass authorization checks, enabling them to view portions of ABAP code that would normally require additional validation. Once logged into the ABAP system, the attacker can run a specific transaction that exposes sensitive system code without proper authorization. This vulnerability compromises the confidentiality.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-31331?
How severe is CVE-2025-31331?
How do I fix CVE-2025-31331?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-31325Due to a Cross-Site Scripting vulnerability in SAP NetWeaver…5.8
- CVE-2025-31326SAP�BusinessObjects Business�Intelligence Platform (Web Inte…4.1
- CVE-2025-31327SAP Field Logistics Manage Logistics application OData meta-…4.3
- CVE-2025-31328SAP Learning Solution is vulnerable to Cross-Site Request Fo…4.6
- CVE-2025-31329SAP NetWeaver is vulnerable to an Information Disclosure vul…6.2
- CVE-2025-31330SAP Landscape Transformation (SLT) allows an attacker with u…9.9
- CVE-2025-31332Due to insecure file permissions in SAP BusinessObjects Busi…7.1
- CVE-2025-31333SAP S4CORE OData meta-data property is vulnerable to data ta…4.3
- CVE-2025-31334Issue that bypasses the "Mark of the Web" security warning f…6.8
- CVE-2025-31335The OpenSAML C++ library before 3.3.1 allows forging of sign…4
- CVE-2025-31338A missing authorization vulnerability in the retrieve teache…6.9
- CVE-2025-31339An unrestricted upload of file with dangerous type vulnerabi…5.3
Are you affected by CVE-2025-31331?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
