Insufficient Validation in SAP HANA JDBC Client
CVE-2025-42895
6.9MEDIUM
What is CVE-2025-42895?
The SAP HANA JDBC Client is exposed to a vulnerability due to inadequate validation of connection property values. This allows a high-privilege, locally authenticated user to inject malicious parameters, potentially leading to unauthorized code execution. While the impact is primarily on the application's availability, there are also implications for data integrity and confidentiality. It is essential to address this issue to maintain a secure environment and prevent potential service disruptions.
Affected Version(s)
SAP HANA JDBC Client HDB_CLIENT 2.0
References
CVSS V3.1
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved