PT-2025-28290 · Sap · Sapcar

Published

2025-07-07

·

Updated

2025-07-25

·

CVE-2025-42971

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SAPCAR (affected versions not specified)
Description: A memory corruption issue exists, allowing an attacker to create malicious SAPCAR archives. When a high-privileged victim extracts this archive, it can lead to out-of-bounds memory read and write, potentially resulting in file extraction and overwrite outside intended directories. This issue has a low impact on the confidentiality, integrity, and availability of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-10655
CVE-2025-42971

Affected Products

Sapcar