CVE-2025-42992
BaseFortify
Publication date: 2025-07-08
Last updated on: 2025-07-08
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | sapcar | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SAPCAR allows an attacker who is already logged in with high privileges to create a malicious SAR archive. The attacker can exploit critical files and directory permissions without breaking signature validation, potentially leading to privilege escalation. It mainly impacts the integrity of the system.
How can this vulnerability impact me? :
The vulnerability can lead to privilege escalation by allowing an attacker to exploit critical files and directory permissions. This can compromise the integrity of the system, potentially allowing unauthorized modification of important files or configurations. The impact on confidentiality and availability is low.