Vulnerability Description
Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host system. Successful exploitation could enable the attacker to execute arbitrary operating system commands on the server, resulting in a complete compromise of the confidentiality, integrity, and availability of the affected system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Business Connector | 4.8 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3666038Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
FAQ
What is CVE-2025-42894?
CVE-2025-42894 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adjacent access could read, write, overwrite, and delete arbitrary files on the host...
How severe is CVE-2025-42894?
CVE-2025-42894 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-42894?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Business Connector.