CVE-2025-43001
SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation.
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.
- CVSS 3.1
- 6.9 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-266
- Source
- cna@sap.com
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.