9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.
AI Analysis
AI processing failed - returned non-JSON response
Basic Information
ID
CVE-2025-42937
Source
sap
Published
Oct 14, 2025 at 00:18
Affected Product
Vendor
SAP_SE
Product
SAP Print Service
Version
SAPSPRINT 8.00
Affected Versions
SAP_SE SAP Print Service SAPSPRINT 8.00
SAP_SE SAP Print Service 8.10
SAP_SE SAP Print Service 8.10