CVE-2025-42916
Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H
- EPSS probability
- 0.27%
- CWE
- CWE-1287
- Published
- 2025-09-09
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP S/4HANA (Private Cloud or On-Premise)
- SAP_SE SAP S/4HANA (Private Cloud or On-Premise)
- SAP_SE SAP S/4HANA (Private Cloud or On-Premise)
- SAP_SE SAP S/4HANA (Private Cloud or On-Premise)
- SAP_SE SAP S/4HANA (Private Cloud or On-Premise)
- SAP_SE SAP S/4HANA (Private Cloud or On-Premise)
- SAP_SE SAP S/4HANA (Private Cloud or On-Premise)
Weakness type
Related vulnerabilities
- CVE-2026-86287 — Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths
- CVE-2026-52763 — YesWiki: SQL injection via the `recentchanges` action `period` argument leading to arbitrary DB read
- CVE-2026-59680 — yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute
- CVE-2026-82741 — Ash.Type.Union with :map_with_tag does not force the tag on dump, enabling tag confusion
- CVE-2026-80051 — github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar...
- CVE-2026-17113 — Cri-o: cri-o: unvalidated image env var causes daemon crash
- CVE-2026-5304 — An ACAP configuration file lacks input validation, which could potentially lead to privilege...
- CVE-2026-18830 — Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API