PT-2025-28301 · Sap · Sapcar
Published
2025-07-08
·
Updated
2025-07-08
·
CVE-2025-43001
CVSS v3.1
6.9
Medium
| Vector | AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions:
SAPCAR (affected versions not specified)
Description:
The issue allows an attacker with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify critical files by tampering with signed archives without breaking the signature. However, it has a low impact on the confidentiality and availability of the system.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sapcar