SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data.
History

Tue, 10 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to drop arbitrary SAP database tables, potentially resulting in a loss of data or rendering the system unusable. On successful exploitation, an attacker can completely delete database entries but is not able to read any data.
Title Missing Authorization check in SAP Business Warehouse and SAP Plug-In Basis
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-06-10T00:11:14.520Z

Updated: 2025-06-10T15:16:00.463Z

Reserved: 2025-04-16T13:25:48.060Z

Link: CVE-2025-42983

cve-icon Vulnrichment

Updated: 2025-06-10T13:27:26.006Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-10T01:15:21.537

Modified: 2025-06-12T16:06:39.330

Link: CVE-2025-42983

cve-icon Redhat

No data.