Path Traversal Vulnerability in SAP Business Connector
CVE-2025-42894

6.8MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 November 2025

What is CVE-2025-42894?

A Path Traversal vulnerability has been identified in SAP Business Connector, which could allow an authenticated attacker with adjacent access to manipulate and access files on the host system. This vulnerability poses a significant risk as successful exploitation enables an attacker to read, write, overwrite, and delete arbitrary files. Consequently, this could lead to the execution of arbitrary operating system commands on the server, undermining the system's confidentiality, integrity, and availability. Users of affected versions should take immediate steps to mitigate the risk and secure their systems.

Affected Version(s)

SAP Business Connector SAP BC 4.8

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.