CVE-2025-42894

MEDIUM

SAP Business Connector - Authenticated Path Traversal and Arbitrary File Write

Title source: llm
STIX 2.1

Description

Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary operating system commands on the server, resulting in a complete compromise of the confidentiality, integrity, and availability of the affected system.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3666038

Scores

CVSS v3 6.8
EPSS 0.0006
EPSS Percentile 20.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
sap/business_connector 4.8
Published Nov 11, 2025
Tracked Since Feb 18, 2026