---
id: CVE-2025-42891
title: >-
  Due to a missing authorization check in SAP Enterprise Search for ABAP, an
  attacker with high privileges may read and export the contents of database
  tables into an ABAP report
summary: >-
  Due to a missing authorization check in SAP Enterprise Search for ABAP, an
  attacker with high privileges may read and export the contents of database
  tables into an ABAP report. This could lead to a high impact on data
  confidentiality an…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-862
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42891'
references:
  - url: 'https://me.sap.com/notes/3659117'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00307
epssPercentile: 0.21508
ingestedAt: '2026-10-07T20:46:46.795Z'
---

## Overview

Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database tables into an ABAP report. This could lead to a high impact on data confidentiality and a low impact on data integrity. There is no impact on application's availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
