CVE-2025-42960

MEDIUM

SAP Business Warehouse - Privilege Escalation

Title source: llm
STIX 2.1

Description

SAP Business Warehouse and SAP BW/4HANA BEx Tools allow an authenticated attacker to gain higher access levels than intended by exploiting improper authorization checks. This could potentially impact data integrity by allowing deletion of user table entries.�It has no impact on the confidentiality and availability of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0017
EPSS Percentile 37.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (20)
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 200
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 300
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 400
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 701
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 702
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 731
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 740
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 750
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 751
SAP_SE/SAP Business Warehouse and SAP BW/4HANA BEx Tools 752
... and 10 more
Published Jul 08, 2025
Tracked Since Feb 18, 2026