# CVE-2025-30016

## Summary

- **CVE ID:** CVE-2025-30016
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-921
- **Published:** Apr 8, 2025
- **Last Modified:** Mar 12, 2026

## Description

SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.

## Affected Products

- SAP_SE — SAP Financial Consolidation (FINANCE 1010)

## References

- [CNA](https://me.sap.com/notes/3572688)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.60%
- **EPSS Percentile:** 46.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._