CVE-2025-42897
BaseFortify
Publication date: 2025-11-11
Last updated on: 2025-11-12
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | business_one | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-522 | The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an information disclosure issue in the anonymous API provided by SAP Business One (SLD). It allows an attacker with normal user access to gain access to unauthorized information. The impact is limited to confidentiality, with no effect on integrity or availability.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of information, which may expose sensitive data to attackers who have normal user access. However, it does not affect the integrity or availability of the application, and the overall impact on confidentiality is considered low.