CVE-2025-42952

HIGH

SAP Business Warehouse & SAP Plug-In Basis - Privilege Escalation

Title source: llm
STIX 2.1

Description

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high impact on availability. Data confidentiality and integrity are not affected. No data can be read, changed or deleted.

References (2)

Core 2
Core References

Scores

CVSS v3 7.7
EPSS 0.0023
EPSS Percentile 45.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (16)
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 701
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 702
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 731
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 740
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 750
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 751
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 752
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 753
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 754
SAP_SE/SAP Business Warehouse and SAP Plug-In Basis 755
... and 6 more
Published Jul 08, 2025
Tracked Since Feb 18, 2026