CVE-2025-30016
SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.60%
- CWE
- CWE-921
- Published
- 2025-04-08
- Last modified
- 2026-03-12
Affected products
- SAP_SE SAP Financial Consolidation
Weakness type
Related vulnerabilities
- CVE-2025-24843 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Storage of Sensitive Data in a Mechanism without Access Control
- CVE-2024-9334 — Information Disclosure in E-Kent's Pallium Vehicle Tracking
- CVE-2025-24870 — Insecure Key & Secret Management vulnerability in SAP GUI for Windows
- CVE-2024-5206 — Sensitive Data Leakage in sklearn.feature_extraction.text.TfidfVectorizer in scikit-learn/scikit-learn
- CVE-2023-41818
- CVE-2023-41965 — Socomec MOD3GP-SY-120K Insecure Storage of Sensitive Information
- CVE-2023-2665 — Storage of Sensitive Data in a Mechanism without Access Control in francoisjacquet/rosariosis
- CVE-2021-27456 — Philips Gemini PET/CT Storage of Sensitive Data in a Mechanism Without Access Control