CVE-2025-42971
BaseFortify
Publication date: 2025-07-08
Last updated on: 2025-07-08
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | sapcar | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a memory corruption issue in SAPCAR that allows an attacker to create malicious SAPCAR archives. When a user with high privileges extracts such a malicious archive, SAPCAR processes it and performs out-of-bounds memory reads and writes. This can cause files to be extracted or overwritten outside the intended directories.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized file extraction and overwriting outside intended directories when a high privileged user extracts a malicious SAPCAR archive. However, it has a low impact on the confidentiality, integrity, and availability of the application.