Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST
July 30, 2026
Missing Authorization and Information Disclosure in RFC Enabled Function Module CMO_COLLECT_INFO_RFC_DEST
Impact on Business
A remote authenticated attacker can discover detailed information about installed software components and their versions on the application server. This information disclosure aids in fingerprinting the system, potentially facilitating further attacks by identifying specific vulnerable components. This has a low impact on the confidentiality of the system.
Vulnerability Details
The RFC-enabled function module CMO_COLLECT_INFO_RFC_DEST lacks proper authorization checks. By executing this function module, a remote authenticated user with low privileges can access technical information regarding the SAP system’s installed components, including add-ons and release versions. This exposure allows an attacker to gather intelligence about the system configuration.
Solution
SAP has released SAP Note 3626440 which provides patched versions of the affected components.
The patches can be downloaded from https://me.sap.com/notes/3626440.
Onapsis strongly recommends SAP customers to download the related security fixes and apply them to the affected components in order to reduce business risks.
Report Timeline
- 03/28/2025: Onapsis reports vulnerability to SAP
- 07/08/2025: SAP issues the patch
References
Advisory Information
- Public Release Date: 07/30/2026
- Security Advisory ID: ONAPSIS-2026-0013
- Researcher(s): Adrian Radulescu
Vulnerability Information
- Vendor: SAP
- Affected Components: SAP NetWeaver AS ABAP, SAP_BASIS (Check SAP Note 3626440 for detailed information on affected releases)
- Vulnerability Class: CWE-284: Improper Access Control
- CVSS v3 score: 4.3 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- Risk Level: Medium
- Assigned CVE: CVE-2025-42986
- Vendor patch Information: SAP Security NOTE 3626440
Affected Components Description
The vulnerability affects SAP NetWeaver AS ABAP and the SAP_BASIS component. Specific versions tested include SAP NetWeaver ABAP 7.52 and SAP Basis 750. Please refer to the vendor patch note for the complete list of affected versions and support packages.

About our Research Labs
Onapsis Research Labs provides the industry analysis of key security issues that impact mission-critical systems and applications. Delivering frequent and timely security and compliance advisories with associated risk levels, Onapsis Research Labs combine in-depth knowledge and experience to deliver technical and business-context with sound security judgment to the broader information security community.
Find all reported vulnerabilities at: https://github.com/Onapsis/vulnerability_advisories
This advisory is licensed under a Creative Commons 4.0 BY-ND International License
