SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application. | |
| Title | Information Disclosure in SAP GRC (AC Plugin) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-06-10T00:10:58.266Z
Updated: 2025-06-12T03:55:17.762Z
Reserved: 2025-04-16T13:25:48.060Z
Link: CVE-2025-42982
Updated: 2025-06-10T14:18:59.465Z
Status : Awaiting Analysis
Published: 2025-06-10T01:15:21.383
Modified: 2025-06-12T16:06:39.330
Link: CVE-2025-42982
No data.