← voltar
CVE-2025-42959highCWE-308

Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 8.1epss 0.5%
probabilidade de exploração
0.5%top 61% das CVEs
exploração observada
nãonenhuma fonte reporta
An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H