CVE-2025-42909
SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.
Scoring
- Severity
- LOW
- CVSS base score
- 3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
- EPSS probability
- 0.23%
- CWE
- CWE-1004
- Published
- 2025-10-14
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP Cloud Appliance Library Appliances
Weakness type
Related vulnerabilities
- CVE-2026-82697 — sambitraj Student-Management-System session_start cookie httponly flag
- CVE-2026-21754 — HCL Hive is affected by multiple security vulnerabilities.
- CVE-2026-57948 — Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
- CVE-2026-11956 — TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
- CVE-2026-42239 — Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
- CVE-2026-39338 — ChurchCRM has Blind XSS via Global Search – Administrative Cookie Session Exfiltration
- CVE-2026-35575 — ChurchCRM has Stored XSS in Group Name
- CVE-2026-25736 — Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute