Home

Description

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.

PUBLISHED Reserved 2025-04-16 | Published 2025-11-11 | Updated 2025-11-12 | Assigner sap




MEDIUM: 6.9CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:H

Problem types

CWE-94: Improper Control of Generation of Code

Product status

Default status
unaffected

HDB_CLIENT 2.0
affected

References

me.sap.com/notes/3643385

url.sap/sapsecuritypatchday

cve.org (CVE-2025-42895)

nvd.nist.gov (CVE-2025-42895)

Download JSON