8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability of the application.
Basic Information
ID
CVE-2025-42951
Source
sap
Published
Aug 12, 2025 at 02:08
Affected Product
Vendor
SAP_SE
Product
SAP Business One (SLD)
Version
B1_ON_HANA 10.0
Affected Versions
SAP_SE SAP Business One (SLD) B1_ON_HANA 10.0
SAP_SE SAP Business One (SLD) SAP-M-BO 10.0
SAP_SE SAP Business One (SLD) SAP-M-BO 10.0