SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap cloud Appliance Library Appliances |
|
| Vendors & Products |
Sap
Sap cloud Appliance Library Appliances |
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted. | |
| Title | Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances | |
| Weaknesses | CWE-1004 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-10-14T00:18:11.957Z
Updated: 2025-10-14T15:24:17.575Z
Reserved: 2025-04-16T13:25:25.737Z
Link: CVE-2025-42909
Updated: 2025-10-14T15:24:14.286Z
Status : Awaiting Analysis
Published: 2025-10-14T01:15:32.710
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-42909
No data.