PT-2025-41842 · Sap · Sap Supplier Relationship Management

Published

2025-10-14

·

Updated

2025-10-14

·

CVE-2025-42910

CVSS v3.1
9.0
VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Supplier Relationship Management (affected versions not specified)
Description SAP Supplier Relationship Management does not properly verify the type or content of uploaded files. This allows an authenticated attacker to upload arbitrary files, including potentially malicious executables. If these files are downloaded and executed by users, they could host malware, leading to severe security breaches impacting confidentiality, integrity, and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-42910

Affected Products

Sap Supplier Relationship Management