SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application.
History

Tue, 10 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application.
Title Information Disclosure in SAP GRC (AC Plugin)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-06-10T00:10:58.266Z

Updated: 2025-06-12T03:55:17.762Z

Reserved: 2025-04-16T13:25:48.060Z

Link: CVE-2025-42982

cve-icon Vulnrichment

Updated: 2025-06-10T14:18:59.465Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-10T01:15:21.383

Modified: 2025-06-12T16:06:39.330

Link: CVE-2025-42982

cve-icon Redhat

No data.