We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-42993

Missing Authorization Check in SAP S/4HANA (Enterprise Event Enablement)



Description

Due to a missing authorization check vulnerability in SAP S/4HANA (Enterprise Event Enablement), an attacker with access to the Inbound Binding Configuration could create an RFC destination and assign an arbitrary high-privilege user. This allows the attacker to consume events via the RFC destination, leading to code execution under the privileges of the assigned high-privilege user. While the vulnerability has a low impact on Availability, it significantly poses a high risk to both Confidentiality and Integrity.

Reserved 2025-04-16 | Published 2025-06-10 | Updated 2025-06-10 | Assigner sap


MEDIUM: 6.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

SAP_GWFND 757
affected

758
affected

References

me.sap.com/notes/3580384

url.sap/sapsecuritypatchday

cve.org (CVE-2025-42993)

nvd.nist.gov (CVE-2025-42993)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-42993

Support options

Helpdesk Chat, Email, Knowledgebase