We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-43000

Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform (PMW)



Description

Under certain conditions Promotion Management Wizard (PMW) allows an attacker to access information which would otherwise be restricted.This has High impact on Confidentiality with Low impact on Integrity and Availability of the application.

Reserved 2025-04-16 | Published 2025-05-13 | Updated 2025-05-13 | Assigner sap


HIGH: 7.9CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

ENTERPRISE 430
affected

2025
affected

2027
affected

References

me.sap.com/notes/3586013

url.sap/sapsecuritypatchday

cve.org (CVE-2025-43000)

nvd.nist.gov (CVE-2025-43000)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-43000

Support options

Helpdesk Chat, Email, Knowledgebase