Authorization Issues in SAP HCM Approve Timesheets Fiori Application
CVE-2025-42917
6.5MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-42917?
The SAP HCM Approve Timesheets Fiori 2.0 application lacks necessary authorization checks for authenticated users. This vulnerability enables attackers to escalate their privileges, compromising the application's integrity. The risk emphasizes the importance of implementing stringent access controls to protect sensitive functionalities within the application, safeguarding overall security.
Affected Version(s)
SAP HCM (Approve Timesheets Fiori 2.0 application) GBX01HR5 605