← back
CVE-2025-42916

Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)

CVSS 8.1 HIGHEPSS 0.2%CWE-1287
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Sep 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →