CVE-2025-42915
Missing Authorization Check in Fiori app (Manage Payment Blocks)
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.4EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
09 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Fiori app Manage Payment Blocks does not perform the necessary authorization checks, allowing an attacker with basic user privileges to abuse functionalities that should be restricted to specific user groups.This issue could impact both the confidentiality and integrity of the application without affecting the availability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Productos afectados
SAP_SE · Fiori app (Manage Payment Blocks)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →