6.5

CVE-2025-42930

Denial of Service (DoS) vulnerability in SAP Business Planning and Consolidation

SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive resources and resulting in system unavailability. This leads to high impact on the availability of the application, there is no impact on confidentiality or integrity.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
Produkt SAP Business Planning and Consolidation
Default Statusunaffected
Version BPC4HANA 200
Status affected
Version 300
Status affected
Version SAP_BW 750
Status affected
Version 751
Status affected
Version 752
Status affected
Version 753
Status affected
Version 754
Status affected
Version 755
Status affected
Version 756
Status affected
Version 757
Status affected
Version 758
Status affected
Version 816
Status affected
Version 914
Status affected
Version CPMBPC 810
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.264
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@sap.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-606 Unchecked Input for Loop Condition

The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.