CVE-2025-31333

MEDIUM

SAP S4CORE - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.

Scores

CVSS v3 4.3
EPSS 0.0021
EPSS Percentile 43.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-472
Status published
Products (2)
SAP_SE/SAP S4CORE entity 108
SAP_SE/SAP S4CORE entity S4CORE 107
Published Apr 08, 2025
Tracked Since Feb 18, 2026