Authorization Flaw in SAP Business Warehouse Process Chains
CVE-2025-25244

5.7MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 March 2025

Summary

The SAP Business Warehouse (Process Chains) contains a vulnerability that allows attackers with display authorization to manipulate process execution. This flaw results from a missing authorization check, enabling the attacker to alter the execution flow of the process chain, thereby skipping essential processes. Such manipulations can result in unexpected outcomes in business reporting, severely affecting data integrity. However, this vulnerability does not compromise data confidentiality or availability. Users of SAP Business Warehouse should review their process chain configurations and apply necessary patches to mitigate this risk.

Affected Version(s)

SAP Business Warehouse (Process Chains) DW4CORE 100

SAP Business Warehouse (Process Chains) 200

SAP Business Warehouse (Process Chains) 300

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.