Privilege Escalation Vulnerability in SAPCAR by SAP
CVE-2025-42992

6.9MEDIUM

Key Information:

Vendor

SAP

Status
Vendor
CVE Published:
8 July 2025

What is CVE-2025-42992?

The vulnerability in SAPCAR allows an attacker with high-level privileges to create a harmful SAR archive, potentially leading to exploitation of critical file and directory permissions. This exploit maintains signature validation, which could result in serious integrity impacts while posing minimal risks to confidentiality and availability. Organizations using SAPCAR should implement security measures and stay updated to mitigate these risks.

Affected Version(s)

SAPCAR SAP_CAR 7.53

SAPCAR 7.22EXT

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42992 : Privilege Escalation Vulnerability in SAPCAR by SAP