CVE-2025-42916Improper Validation of Specified Type of Input in SE SAP S 4hana

Severity
8.1HIGHNVD
EPSS
0.0%
top 87.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 9

Description

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:HExploitability: 1.7 | Impact: 5.8

Affected Packages1 packages

CVEListV5sap_se/sap_s_4hana7 versions+6

🔴Vulnerability Details

2
CVEList
Missing input validation vulnerability in SAP S/4HANA (Private Cloud or On-Premise)2025-09-09
GHSA
GHSA-h2j4-wh32-g972: Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the2025-09-09
CVE-2025-42916 — SAP SE SAP S 4hana vulnerability | cvebase