SAP BI Platform Vulnerability in LogonToken IP Address Modification
CVE-2025-42907

4.3MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
23 September 2025

What is CVE-2025-42907?

The SAP BI Platform contains a vulnerability that allows attackers to manipulate the IP address within the LogonToken for OpenDoc functionality. When the altered link is accessed, it could send unexpected requests to a different server, which, while having minimal impact on data integrity, poses a potential risk by enabling misleading communications. Users are encouraged to review their configurations and apply the latest security patches to mitigate risks associated with this vulnerability.

Affected Version(s)

SAP BI Platform ENTERPRISE 430

SAP BI Platform 2025

SAP BI Platform 2027

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42907 : SAP BI Platform Vulnerability in LogonToken IP Address Modification