CVE-2025-42912
BaseFortify
Publication date: 2025-09-09
Last updated on: 2025-09-09
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | hcm_my_timesheet_fiori | 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SAP HCM My Timesheet Fiori 2.0 application where it fails to perform necessary authorization checks for an authenticated user. This flaw allows an authenticated user to escalate their privileges within the application.
How can this vulnerability impact me? :
The vulnerability can lead to escalation of privileges, impacting the integrity of the application. This means an attacker or unauthorized user with valid credentials could gain higher-level access or perform actions beyond their intended permissions. Confidentiality and availability are not affected.