Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap hana Sap s/4 Hana |
|
| Vendors & Products |
Sap
Sap hana Sap s/4 Hana |
Tue, 09 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected. | |
| Title | Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger) | |
| Weaknesses | CWE-405 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-12-09T16:02:29.682Z
Reserved: 2025-04-16T13:25:17.023Z
Link: CVE-2025-42876
Updated: 2025-12-09T14:23:44.538Z
Status : Deferred
Published: 2025-12-09T16:17:51.857
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-42876
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:04:27Z