CVE-2025-42996
SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to access or modify non-sensitive information or consume sufficient resources which could degrade the performance of the server causing low impact on confidentiality, integrity and availibility of the application.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
- EPSS probability
- 0.22%
- CWE
- CWE-590
- Published
- 2025-06-10
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP MDM Server
Weakness type
Related vulnerabilities
- CVE-2026-89161 — In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a...
- CVE-2026-18582 — mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap
- CVE-2025-7006 — Avast antivirus use of stack memory after free when scanning a malformed PE file
- CVE-2026-47328 — Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling
- CVE-2026-20810 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2025-54899 — Microsoft Excel Remote Code Execution Vulnerability
- CVE-2025-42995 — Multiple vulnerabilities in SAP MDM Server
- CVE-2025-42994 — Multiple vulnerabilities in SAP MDM Server