8.5
CVE-2025-42983
- EPSS 0.06%
- Published 10.06.2025 00:11:14
- Last modified 12.06.2025 16:06:39
- Source cna@sap.com
- Teams watchlist Login
- Open Login
SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorSAP_SE
≫
Product
SAP Business Warehouse and SAP Plug-In Basis
Default Statusunaffected
Version
PI_BASIS 2006_1_700
Status
affected
Version
701
Status
affected
Version
702
Status
affected
Version
731
Status
affected
Version
740
Status
affected
Version
SAP_BW 750
Status
affected
Version
751
Status
affected
Version
752
Status
affected
Version
753
Status
affected
Version
754
Status
affected
Version
755
Status
affected
Version
756
Status
affected
Version
757
Status
affected
Version
758
Status
affected
Version
914
Status
affected
Version
915
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.168 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
cna@sap.com | 8.5 | 3.1 | 4.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.