CVE-2025-42965

MEDIUM

SAP CMC Promotion Management - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to information disclosure. This vulnerability does not impact the integrity or availability of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 4.1
EPSS 0.0019
EPSS Percentile 40.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (3)
SAP_SE/SAP BusinessObjects BI Platform Central Management Console Promotion Management Application 2025
SAP_SE/SAP BusinessObjects BI Platform Central Management Console Promotion Management Application 2027
SAP_SE/SAP BusinessObjects BI Platform Central Management Console Promotion Management Application ENTERPRISE 430
Published Jul 08, 2025
Tracked Since Feb 18, 2026