VulnerabilityDeferred
CVE-2025-42909
SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances.
LOW 3.0EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.
- CVSS 3.1
- 3.0 LOWCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
- EPSS
- 0.23% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1004
- Source
- cna@sap.com
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.