Improper Authorization in SAP Business Warehouse and BW/4HANA BEx Tools
CVE-2025-42960

4.3MEDIUM

What is CVE-2025-42960?

The vulnerability in SAP Business Warehouse and SAP BW/4HANA BEx Tools allows an authenticated user to exploit insufficient authorization checks. This could enable the attacker to elevate their access privileges, potentially leading to unintended modifications or deletions of user table entries, thereby jeopardizing data integrity. While it does not affect the confidentiality or availability of the application, it poses a significant risk to the integrity of the data managed within these systems.

Affected Version(s)

SAP Business Warehouse and SAP BW/4HANA BEx Tools DW4CORE 100

SAP Business Warehouse and SAP BW/4HANA BEx Tools 200

SAP Business Warehouse and SAP BW/4HANA BEx Tools 300

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42960 : Improper Authorization in SAP Business Warehouse and BW/4HANA BEx Tools