Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause high impact on confidentiality, integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap supplier Relationship Management |
|
| Vendors & Products |
Sap
Sap supplier Relationship Management |
Tue, 14 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause high impact on confidentiality, integrity and availability of the application. | |
| Title | Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-10-14T00:18:21.887Z
Updated: 2025-10-21T03:55:25.261Z
Reserved: 2025-04-16T13:25:25.737Z
Link: CVE-2025-42910
Updated: 2025-10-14T15:24:37.446Z
Status : Awaiting Analysis
Published: 2025-10-14T01:15:32.880
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-42910
No data.