6.9

CVSS3.1

CVE-2025-42992 - Multiple Privilege Escalation Vulnerabilities in SAPCAR

SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-42986 - Missing Authorization check in SAP NetWeaver and ABAP Platform

Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: Oct. 27, 2025, 4:55 p.m.

6.1

CVSS3.1

CVE-2025-42985 - Open Redirect vulnerability in SAP BusinessObjects Content Administrator workbench

Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim๏ฟฝs browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality andโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2025-42981 - Multiple vulnerabilities in SAP NetWeaver Application Server ABAP

Due to an open redirect vulnerability in SAP NetWeaver Application Server ABAP, an unauthenticated attacker could craft a URL link embedding a malicious script at a location not properly sanitized. When a victim clicks on this link, the script executes within the victim's browser, redirecting them โ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-42980 - Insecure Deserialization in SAP NetWeaver Enterprise Portal Federated Portal Network

SAP NetWeaver Enterprise Portal Federated Portal Network is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

๐Ÿ“… Published: July 8, 2025, 12:38 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.6

CVSS3.1

CVE-2025-42979 - Insecure Key & Secret Management vulnerability in SAP GUI for Windows

The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of โ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-42978 - Insufficiently Secure Hostname Verification for Outbound TLS Connections in SAP NetWeaver Applicatiโ€ฆ

The widely used component that establishes outbound TLS connections in SAP NetWeaver Application Server Java does not reliably match the hostname that is used for the connection against the wildcard hostname defined in the received certificate of remote TLS server. This might lead to the outbound cโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-42974 - Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN)

Due to missing authorization check, an attacker authenticated as a non-administrative user could call a remote-enabled function module. This could enable access to information normally restricted, resulting in low impact on confidentiality. There is no impact on integrity or availability.

๐Ÿ“… Published: July 8, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2025-42973 - Cross-Site Scripting (XSS) vulnerability in SAP Data Services (DQ Report)

Due to a Cross-Site Scripting vulnerability in SAP Data Services Management Console, an authenticated attacker could exploit the search functionality associated with DQ job status reports. By intercepting requests, malicious script can be injected and subsequently executed when a user loads the affโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS3.1

CVE-2025-42971 - Memory Corruption vulnerability in SAPCAR

A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it gets processed by SAPCAR on their system, resulting in out-of-bounds memory read and write. This could lead to file extractioโ€ฆ

๐Ÿ“… Published: July 8, 2025, 12:37 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4755 of 34,919
ยซ previous page ยป next page
Filters