SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Oct 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted. | |
Title | Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances | |
Weaknesses | CWE-1004 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-10-14T00:18:11.957Z
Updated: 2025-10-14T15:24:17.575Z
Reserved: 2025-04-16T13:25:25.737Z
Link: CVE-2025-42909

Updated: 2025-10-14T15:24:14.286Z

Status : Awaiting Analysis
Published: 2025-10-14T01:15:32.710
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-42909

No data.