CVE-2025-42984
Missing Authorization check in SAP S/4HANA (Manage Central Purchase Contract application)
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAP S/4HANA Manage Central Purchase Contract does not perform necessary authorization checks for an authenticated user. Due to this, an attacker could execute the function import on the entity making it inaccessible for unrestricted user. This has low impact on confidentiality and availability of the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Affected products
SAP_SE · SAP S/4HANA (Manage Central Purchase Contract application)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →