CVE-2025-42967

SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application.
Configurations

No configuration.

History

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) La propagación de características de SAP S/4HANA y SAP SCM presenta una vulnerabilidad de ejecución remota de código. Esto permite a un atacante con altos privilegios crear un nuevo informe con su propio código, obteniendo así el control total del sistema SAP afectado, lo que afecta gravemente la confidencialidad, la integridad y la disponibilidad de la aplicación.

08 Jul 2025, 10:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.1
v2 : unknown
v3 : 9.9
Summary (en) SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with high privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application. (en) SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application.

08 Jul 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 01:15

Updated : 2025-07-08 16:18


NVD link : CVE-2025-42967

Mitre link : CVE-2025-42967

CVE.ORG link : CVE-2025-42967


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')