9.9

CVE-2025-42967

Medienbericht

SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
Produkt SAP S/4HANA and SAP SCM (Characteristic Propagation)
Default Statusunaffected
Version SCMAPO 713
Status affected
Version 714
Status affected
Version S4CORE 102
Status affected
Version 103
Status affected
Version 104
Status affected
Version S4COREOP 105
Status affected
Version 106
Status affected
Version 107
Status affected
Version 108
Status affected
Version SCM 700
Status affected
Version 701
Status affected
Version 702
Status affected
Version 712
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.592
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@sap.com 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.