CVE-2025-43007

MEDIUM

SAP Service Parts Management (SPM) - Authenticated Privilege Escalation via Missing Authorization

Title source: llm
STIX 2.1

Description

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on confidentiality, integrity and availability of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 6.3
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (6)
SAP_SE/SAP Service Parts Management (SPM) 101
SAP_SE/SAP Service Parts Management (SPM) 102
SAP_SE/SAP Service Parts Management (SPM) 103
SAP_SE/SAP Service Parts Management (SPM) 618
SAP_SE/SAP Service Parts Management (SPM) S4CORE 100
SAP_SE/SAP Service Parts Management (SPM) SAP_APPL 617
Published May 13, 2025
Tracked Since Feb 18, 2026