CVE-2025-42897

MEDIUM

SAP Business One - Info Disclosure

Title source: llm
STIX 2.1

Description

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the integrity and availability.

Scores

CVSS v3 5.3
EPSS 0.0004
EPSS Percentile 11.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (2)
SAP_SE/SAP Business One (SLD) B1_ON_HANA 10.0
SAP_SE/SAP Business One (SLD) SAP-M-BO 10.0
Published Nov 11, 2025
Tracked Since Feb 18, 2026