Authorization Flaw in SAP Business Warehouse Process Chains
CVE-2025-25244
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 11 March 2025
Summary
The SAP Business Warehouse (Process Chains) contains a vulnerability that allows attackers with display authorization to manipulate process execution. This flaw results from a missing authorization check, enabling the attacker to alter the execution flow of the process chain, thereby skipping essential processes. Such manipulations can result in unexpected outcomes in business reporting, severely affecting data integrity. However, this vulnerability does not compromise data confidentiality or availability. Users of SAP Business Warehouse should review their process chain configurations and apply necessary patches to mitigate this risk.
Affected Version(s)
SAP Business Warehouse (Process Chains) DW4CORE 100
SAP Business Warehouse (Process Chains) 200
SAP Business Warehouse (Process Chains) 300
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved