CVE-2025-42946

MEDIUM

SAP S/4HANA (Bank Communication Management) - Path Traversal

Title source: llm
STIX 2.1

Description

Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attacker to potentially read or delete these files hence causing a high impact on confidentiality and low impact on integrity. There is no impact on availability of the system.

References (2)

Core 2
Core References

Scores

CVSS v3 6.9
EPSS 0.0013
EPSS Percentile 32.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (12)
SAP_SE/SAP S/4HANA (Bank Communication Management) 103
SAP_SE/SAP S/4HANA (Bank Communication Management) 104
SAP_SE/SAP S/4HANA (Bank Communication Management) 105
SAP_SE/SAP S/4HANA (Bank Communication Management) 106
SAP_SE/SAP S/4HANA (Bank Communication Management) 107
SAP_SE/SAP S/4HANA (Bank Communication Management) 108
SAP_SE/SAP S/4HANA (Bank Communication Management) 618
SAP_SE/SAP S/4HANA (Bank Communication Management) 720
SAP_SE/SAP S/4HANA (Bank Communication Management) 730
SAP_SE/SAP S/4HANA (Bank Communication Management) S4CORE 102
... and 2 more
Published Aug 12, 2025
Tracked Since Feb 18, 2026