5.1

CVSS3.1

CVE-2025-31719 -

In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature results with low probability.

πŸ“… Published: Nov. 11, 2025, 12:33 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-42940 - Memory Corruption vulnerability in SAP CommonCryptoLib

SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 data over the network. This may result in memory corruption followed by an application crash, hence leading to a high impact on availability. There is no impact on confidentiality o…

πŸ“… Published: Nov. 11, 2025, 12:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-42924 - Open Redirect vulnerabilities in SAP S/4HANA landscape (SAP E-Recruiting BSP)

SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the victim could be redirected to the page controlled by the attacker. This has low impact on confidentiality and integrity of the application with no impact on availability.

πŸ“… Published: Nov. 11, 2025, 12:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-42919 - Information Disclosure vulnerability in SAP NetWeaver Application Server Java

Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could be accessed via manipulated URLs. An unauthenticated attacker could exploit this vulnerability by inserting arbitrary path components in the request, allowing unauthorized access t…

πŸ“… Published: Nov. 11, 2025, 12:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-42899 - Missing Authorization check in SAP S4CORE (Manage Journal Entries)

SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. This has low impact on confidentiality of the application with no impact on integrity and availability of the application.

πŸ“… Published: Nov. 11, 2025, 12:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-42897 - Information Disclosure vulnerability in SAP Business One (SLD)

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the integrity and availabil…

πŸ“… Published: Nov. 11, 2025, 12:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS3.1

CVE-2025-42895 - Code Injection vulnerability in SAP HANA JDBC Client

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of …

πŸ“… Published: Nov. 11, 2025, 12:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS3.1

CVE-2025-42894 - Path Traversal vulnerability in SAP Business Connector

Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary operating system co…

πŸ“… Published: Nov. 11, 2025, 12:19 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:46 p.m.

6.1

CVSS3.1

CVE-2025-42893 - Open Redirect vulnerability in SAP Business Connector

Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL that, if accessed by a victim, redirects them to an attacker-controlled site displayed within an embedded frame. Successful exploitation could allow the attacker to steal sensiti…

πŸ“… Published: Nov. 11, 2025, 12:17 a.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:53 p.m.

6.8

CVSS3.1

CVE-2025-42892 - OS Command Injection vulnerability in SAP Business Connector

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this content enables execution of arbitrary operating syste…

πŸ“… Published: Nov. 11, 2025, 12:17 a.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:53 p.m.
Total resulsts: 349182
Page 3083 of 34,919
Β« previous page Β» next page
Filters