Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Nov 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap starter Solution |
|
| Vendors & Products |
Sap
Sap starter Solution |
Tue, 11 Nov 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end database. As a result, this vulnerability has a low impact on the application's confidentiality and integrity but no impact on its availability. | |
| Title | SQL Injection vulnerability in SAP Starter Solution (PL SAFT) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-11-12T20:11:06.168Z
Reserved: 2025-04-16T13:25:19.826Z
Link: CVE-2025-42889
Updated: 2025-11-12T17:32:09.715Z
Status : Deferred
Published: 2025-11-11T01:15:37.663
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-42889
No data.
OpenCVE Enrichment
Updated: 2025-11-12T12:48:01Z