cbcvebase.
CVE-2025-42916
published 2025-09-09

CVE-2025-42916: Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables…

PriorityP342high8.1CVSS 3.1
AVAACLPRHUINSCCNIHAH
EPSS
0.25%
16.1th percentile
Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.

Affected

7 ranges
VendorProductVersion rangeFixed in
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
sap_sesap_s_4hana
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.