We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-42951

Broken Authorization in SAP Business One (SLD)



Description

Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability of the application.

Reserved 2025-04-16 | Published 2025-08-12 | Updated 2025-08-12 | Assigner sap


HIGH: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-863: Incorrect Authorization

Product status

Default status
unaffected

B1_ON_HANA 10.0
affected

SAP-M-BO 10.0
affected

References

me.sap.com/notes/3625403

url.sap/sapsecuritypatchday

cve.org (CVE-2025-42951)

nvd.nist.gov (CVE-2025-42951)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-42951

Support options

Helpdesk Chat, Email, Knowledgebase