CVE-2025-42909
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-10-14
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | sap_cloud_appliance_library | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1004 | The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in SAP Cloud Appliance Library Appliances where an attacker with high privileges can exploit an insecure default profile setting in SAP S/4HANA appliances to gain access to other appliances. The vulnerability leverages a default configuration issue allowing lateral access between appliances.
How can this vulnerability impact me? :
The impact on confidentiality is low, meaning limited exposure of sensitive information. There is no impact on integrity or availability of the application. However, an attacker with high privileges could gain unauthorized access to other appliances, potentially leading to unauthorized use or information exposure within the environment.