CVE-2025-43001
BaseFortify
Publication date: 2025-07-08
Last updated on: 2025-07-08
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | sapcar | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-266 | A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in SAPCAR allows an attacker who is already logged in with high privileges to override the permissions of the current and parent directories during the extraction of an archive. This can lead to privilege escalation by enabling the attacker to modify critical files through tampering with signed archives without breaking their signature.
How can this vulnerability impact me? :
The vulnerability can lead to privilege escalation, allowing an attacker to modify critical system files. While it has a low impact on confidentiality and availability, the integrity of important files can be compromised, potentially affecting system security and stability.