SAP MDM Server Vulnerability in ReadString Function
CVE-2025-42994

7.5HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 June 2025

What is CVE-2025-42994?

The SAP MDM Server contains a vulnerability in its ReadString function that can be exploited by an attacker sending specially crafted packets. This may lead to a memory read access violation, causing the server process to crash unexpectedly. While this issue affects the server's availability, it does not compromise the confidentiality or integrity of the application.

Affected Version(s)

SAP MDM Server MDM_SERVER 710.750

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42994 : SAP MDM Server Vulnerability in ReadString Function