CVE-2025-42892

MEDIUM

SAP Business Connector - Authenticated OS Command Injection via Crafted Content Upload

Title source: llm
STIX 2.1

Description

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating system commands. Successful exploitation could lead to full compromise of the system�s confidentiality, integrity, and availability.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3665900

Scores

CVSS v3 6.8
EPSS 0.0007
EPSS Percentile 21.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
sap/business_connector 4.8
Published Nov 11, 2025
Tracked Since Feb 18, 2026