Resource Consumption Vulnerability in SAP Business Planning and Consolidation
CVE-2025-42930

6.5MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 September 2025

What is CVE-2025-42930?

SAP Business Planning and Consolidation is susceptible to a resource consumption vulnerability, where an authenticated standard user can invoke a function module by providing specific parameters. This action triggers a loop that consumes a significant amount of resources, leading to potential unavailability of the application. While this vulnerability does not compromise the confidentiality or integrity of the system, it poses a serious risk to the application's availability, severely impacting business operations and user access.

Affected Version(s)

SAP Business Planning and Consolidation BPC4HANA 200

SAP Business Planning and Consolidation 300

SAP Business Planning and Consolidation SAP_BW 750

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42930 : Resource Consumption Vulnerability in SAP Business Planning and Consolidation