CVE-2025-42914
BaseFortify
Publication date: 2025-09-09
Last updated on: 2025-09-09
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | hcm_my_timesheet_fiori | 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SAP HCM My Timesheet Fiori 2.0 application due to missing authorization checks. It allows an authenticated attacker who has in-depth system knowledge to escalate their privileges and perform restricted activities within the application. The impact is limited to a low impact on the integrity of the application, with no effect on confidentiality or availability.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing an authenticated attacker to escalate privileges and perform actions that should be restricted, potentially altering or affecting the integrity of the application. However, it does not impact the confidentiality or availability of the system.