Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap s/4hana |
|
Vendors & Products |
Sap
Sap s/4hana |
Tue, 09 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 09 Sep 2025 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality. | |
Title | Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise) | |
Weaknesses | CWE-1287 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-09-09T02:07:53.085Z
Updated: 2025-09-09T13:47:28.351Z
Reserved: 2025-04-16T13:25:30.252Z
Link: CVE-2025-42916

Updated: 2025-09-09T13:47:24.551Z

Status : Awaiting Analysis
Published: 2025-09-09T02:15:39.717
Modified: 2025-09-09T16:28:43.660
Link: CVE-2025-42916

No data.