SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted.
Title Missing Authorization check in SAP S4/HANA (OData meta-data property)
Weaknesses CWE-472
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-05-13T14:02:42.025Z

Reserved: 2025-04-16T13:25:53.589Z

Link: CVE-2025-43002

cve-icon Vulnrichment

Updated: 2025-05-13T14:02:38.345Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T01:15:48.727

Modified: 2025-05-13T19:35:18.080

Link: CVE-2025-43002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.