SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout displaying this field. On performing this step the attacker could gain access to highly sensitive information. This could cause a high impact on confidentiality and minimal impact on integrity and availability of the application.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout displaying this field. On performing this step the attacker could gain access to highly sensitive information. This could cause a high impact on confidentiality and minimal impact on integrity and availability of the application.
Title Information Disclosure vulnerability in SAP S/4HANA (Private Cloud & On-Premise)
Weaknesses CWE-749
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-05-13T14:02:18.513Z

Reserved: 2025-04-16T13:25:53.589Z

Link: CVE-2025-43003

cve-icon Vulnrichment

Updated: 2025-05-13T14:02:12.402Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T01:15:48.873

Modified: 2025-05-13T19:35:18.080

Link: CVE-2025-43003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.