6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Description
SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.
Basic Information
ID
CVE-2025-42912
Source
sap
Published
Sep 9, 2025 at 02:06
Affected Product
Vendor
SAP_SE
Product
SAP HCM (My Timesheet Fiori 2.0 application)
Version
GBX01HR5 605
Affected Versions
SAP_SE SAP HCM (My Timesheet Fiori 2.0 application) GBX01HR5 605