cbcvebase.
CVE-2025-42970
published 2025-07-08

CVE-2025-42970: SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing…

PriorityP429medium5.8CVSS 3.1
AVLACLPRHUIRSUCNIHAH
EPSS
0.29%
21.1th percentile
SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.

Affected

2 ranges
VendorProductVersion rangeFixed in
sap_sesapcar
sap_sesapcar
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.