SAP has issued a major security vulnerability announcement (CVE-2025-42989, CVSS: 9.6) for its NetWeaver ABAP Application Server product. This vulnerability stems from the SAP Remote Function Call (
RFC) process, which allows authenticated attackers to bypass checking procedures, leading to privilege escalation. If successfully exploited, it would severely impact the integrity and availability of the application.