CVE-2025-42947

MEDIUM

SAP FICA ODN framework - Authenticated Code Injection via Local Variable Manipulation

Title source: llm
STIX 2.1

Description

SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 5.5
EPSS 0.0029
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (12)
SAP_SE/SAP FICA ODN framework 103
SAP_SE/SAP FICA ODN framework 104
SAP_SE/SAP FICA ODN framework 105
SAP_SE/SAP FICA ODN framework 106
SAP_SE/SAP FICA ODN framework 107
SAP_SE/SAP FICA ODN framework 108
SAP_SE/SAP FICA ODN framework 616
SAP_SE/SAP FICA ODN framework 617
SAP_SE/SAP FICA ODN framework 618
SAP_SE/SAP FICA ODN framework FI-CA 606
... and 2 more
Published Jul 23, 2025
Tracked Since Feb 18, 2026