Insufficient Validation in SAP HANA JDBC Client
CVE-2025-42895

6.9MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 November 2025

What is CVE-2025-42895?

The SAP HANA JDBC Client is exposed to a vulnerability due to inadequate validation of connection property values. This allows a high-privilege, locally authenticated user to inject malicious parameters, potentially leading to unauthorized code execution. While the impact is primarily on the application's availability, there are also implications for data integrity and confidentiality. It is essential to address this issue to maintain a secure environment and prevent potential service disruptions.

Affected Version(s)

SAP HANA JDBC Client HDB_CLIENT 2.0

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.