Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap s/4hana |
|
| Vendors & Products |
Sap
Sap s/4hana |
Tue, 09 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality. | |
| Title | Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise) | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-09-09T02:07:53.085Z
Updated: 2025-09-09T13:47:28.351Z
Reserved: 2025-04-16T13:25:30.252Z
Link: CVE-2025-42916
Updated: 2025-09-09T13:47:24.551Z
Status : Awaiting Analysis
Published: 2025-09-09T02:15:39.717
Modified: 2025-09-09T16:28:43.660
Link: CVE-2025-42916
No data.