CVE-2025-42996
BaseFortify
Publication date: 2025-06-10
Last updated on: 2025-06-12
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-590 | The product calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc(). |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SAP MDM Server allows an attacker to take control of existing client sessions and perform certain functions without needing to re-authenticate. This means the attacker can access or modify non-sensitive information or use resources in a way that degrades server performance.
How can this vulnerability impact me? :
The impact includes unauthorized access or modification of non-sensitive information and potential degradation of server performance due to resource consumption. Overall, it results in a low impact on confidentiality, integrity, and availability of the application.