CVE-2025-42995

HIGH

SAP MDM Server >= 710.750 - Denial of Service via Crafted Packet Handling

Title source: llm
STIX 2.1

Description

SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 47.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-590
Status published
Products (1)
SAP_SE/SAP MDM Server MDM_SERVER 710.750
Published Jun 10, 2025
Tracked Since Feb 18, 2026