Description
SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.
Published: 2025-07-23
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-22407 SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.
History

Wed, 23 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap fica Odn Framework
Vendors & Products Sap
Sap fica Odn Framework

Wed, 23 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Jul 2025 04:00:00 +0000

Type Values Removed Values Added
Description SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.
Title Code Injection vulnerability in SAP FICA ODN framework
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Sap Fica Odn Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-07-23T15:20:22.443Z

Reserved: 2025-04-16T13:25:37.188Z

Link: CVE-2025-42947

cve-icon Vulnrichment

Updated: 2025-07-23T15:17:49.734Z

cve-icon NVD

Status : Deferred

Published: 2025-07-23T04:15:44.770

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-42947

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-23T17:35:56Z

Weaknesses