SAP Business Warehouse and Plug-In Basis Vulnerability Exposes Database to Attacks
CVE-2025-42952

7.7HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 July 2025

What is CVE-2025-42952?

An authenticated attacker can exploit a vulnerability in SAP Business Warehouse and SAP Plug-In Basis, enabling them to add fields to arbitrary SAP database tables and structures. This capability can lead to system instability, as it allows the potential triggering of short dumps during login attempts, which disrupts user access and may result in system outages. While data confidentiality and integrity remain intact, the risk to system availability poses significant operational challenges for organizations relying on these SAP products.

Affected Version(s)

SAP Business Warehouse and SAP Plug-In Basis PI_BASIS 2006_1_700

SAP Business Warehouse and SAP Plug-In Basis 701

SAP Business Warehouse and SAP Plug-In Basis 702

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42952 : SAP Business Warehouse and Plug-In Basis Vulnerability Exposes Database to Attacks