CVE-2025-42913
BaseFortify
Publication date: 2025-09-09
Last updated on: 2025-09-09
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | hcm_my_timesheet_fiori | 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SAP HCM My Timesheet Fiori 2.0 application due to missing authorization checks. It allows an authenticated attacker who has in-depth system knowledge to escalate their privileges and perform actions that should normally be restricted. The impact is limited to a low impact on the integrity of the application, with no effect on confidentiality or availability.
How can this vulnerability impact me? :
The vulnerability can allow an authenticated attacker to escalate privileges within the SAP HCM My Timesheet Fiori 2.0 application and perform restricted activities. This results in a low impact on the integrity of the application, meaning some data or functions could be altered improperly. However, confidentiality and availability of the system are not affected.