Privilege Escalation Vulnerability in SAP HCM My Timesheet Fiori Application
CVE-2025-42913

3.1LOW

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 September 2025

What is CVE-2025-42913?

The SAP HCM My Timesheet Fiori application is susceptible to a privilege escalation vulnerability caused by inadequate authorization checks. This allows an authenticated user with advanced knowledge of the system to gain unauthorized access to restricted functionalities. Despite the low impact on application integrity, it raises significant concerns regarding operational security and highlights the importance of robust authorization mechanisms in enterprise applications.

Affected Version(s)

SAP HCM (My Timesheet Fiori 2.0 application) GBX01HR5 605

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42913 : Privilege Escalation Vulnerability in SAP HCM My Timesheet Fiori Application