CVE-2025-43009

MEDIUM

SAP Service Parts Management (SPM) - Missing Authorization

Title source: llm
STIX 2.1

Description

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 6.3
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (12)
SAP_SE/SAP Service Parts Management (SPM) 101
SAP_SE/SAP Service Parts Management (SPM) 102
SAP_SE/SAP Service Parts Management (SPM) 602
SAP_SE/SAP Service Parts Management (SPM) 603
SAP_SE/SAP Service Parts Management (SPM) 604
SAP_SE/SAP Service Parts Management (SPM) 605
SAP_SE/SAP Service Parts Management (SPM) 606
SAP_SE/SAP Service Parts Management (SPM) 616
SAP_SE/SAP Service Parts Management (SPM) 617
SAP_SE/SAP Service Parts Management (SPM) 618
... and 2 more
Published May 13, 2025
Tracked Since Feb 18, 2026