CVE-2025-42947
Code Injection vulnerability in SAP FICA ODN framework
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.5EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
23 jul 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
Productos afectados
SAP_SE · SAP FICA ODN framework¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →