SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 14 Oct 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted. | |
Title | Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances | |
Weaknesses | CWE-1004 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-10-14T00:18:11.957Z
Reserved: 2025-04-16T13:25:25.737Z
Link: CVE-2025-42909

No data.

Status : Received
Published: 2025-10-14T01:15:32.710
Modified: 2025-10-14T01:15:32.710
Link: CVE-2025-42909

No data.

No data.