Privilege Escalation in SAP HCM My Timesheet Fiori Application by SAP
CVE-2025-42912

6.5MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 September 2025

What is CVE-2025-42912?

The SAP HCM My Timesheet Fiori 2.0 application has a security flaw that lacks essential authorization checks for authenticated users, which could lead to unauthorized privilege escalation. Although this vulnerability predominantly affects the application's integrity, both confidentiality and availability remain intact. Organizations utilizing this application should prioritize reviewing their security protocols and user access levels to mitigate potential unauthorized manipulations.

Affected Version(s)

SAP HCM (My Timesheet Fiori 2.0 application) GBX01HR5 605

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42912 : Privilege Escalation in SAP HCM My Timesheet Fiori Application by SAP