SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to information disclosure. This vulnerability does not impact the integrity or availability of the application.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Fri, 11 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 08 Jul 2025 00:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to information disclosure. This vulnerability does not impact the integrity or availability of the application. | |
| Title | Server Side Request Forgery(SSRF) vulnerability in SAP BusinessObjects BI Platform Central Management Console Promotion Management Application | |
| Weaknesses | CWE-918 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: sap
Published: 2025-07-08T00:36:02.707Z
Updated: 2025-07-11T13:29:48.390Z
Reserved: 2025-04-16T13:25:42.158Z
Link: CVE-2025-42965
Updated: 2025-07-11T13:29:44.289Z
Status : Awaiting Analysis
Published: 2025-07-08T01:15:23.440
Modified: 2025-07-08T16:18:14.207
Link: CVE-2025-42965
No data.