Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database tables into an ABAP report. This could lead to a high impact on data confidentiality and a low impact on data integrity. There is no impact on application's availability.
History

Tue, 09 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap enterprise Search For Abap
Vendors & Products Sap
Sap enterprise Search For Abap

Tue, 09 Dec 2025 02:30:00 +0000

Type Values Removed Values Added
Description Due to a missing authorization check in SAP Enterprise Search for ABAP, an attacker with high privileges may read and export the contents of database tables into an ABAP report. This could lead to a high impact on data confidentiality and a low impact on data integrity. There is no impact on application's availability.
Title Missing Authorization check in SAP Enterprise Search for ABAP
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-12-09T02:15:18.798Z

Updated: 2025-12-09T16:00:38.560Z

Reserved: 2025-04-16T13:25:22.788Z

Link: CVE-2025-42891

cve-icon Vulnrichment

Updated: 2025-12-09T16:00:33.719Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:17:52.610

Modified: 2025-12-09T18:36:53.557

Link: CVE-2025-42891

cve-icon Redhat

No data.