CVE-2025-43011

HIGH

SAP Landscape Transformation - Privilege Escalation

Title source: llm
STIX 2.1

Description

Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the integrity or availability of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 7.7
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (13)
SAP_SE/SAP Landscape Transformation (PCL Basis) 103
SAP_SE/SAP Landscape Transformation (PCL Basis) 104
SAP_SE/SAP Landscape Transformation (PCL Basis) 105
SAP_SE/SAP Landscape Transformation (PCL Basis) 106
SAP_SE/SAP Landscape Transformation (PCL Basis) 107
SAP_SE/SAP Landscape Transformation (PCL Basis) 108
SAP_SE/SAP Landscape Transformation (PCL Basis) 2011_1_710
SAP_SE/SAP Landscape Transformation (PCL Basis) 2011_1_730
SAP_SE/SAP Landscape Transformation (PCL Basis) 2011_1_731
SAP_SE/SAP Landscape Transformation (PCL Basis) 2018_1_752
... and 3 more
Published May 13, 2025
Tracked Since Feb 18, 2026