← back
CVE-2025-43001

Multiple Privilege Escalation Vulnerabilities in SAPCAR

CVSS 6.9 MEDIUMEPSS 0.1%CWE-266
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.9EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L
Affected products
SAP_SE · SAPCAR

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →