Memory Access Violation in SAP MDM Server by SAP
CVE-2025-42995

7.5HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 June 2025

What is CVE-2025-42995?

An identified vulnerability in the SAP MDM Server's Read function allows attackers to manipulate specially crafted packets. This could result in a memory access violation, causing the server process to fail and exit unexpectedly. While this flaw does not compromise the confidentiality or integrity of the application, it significantly impacts availability, posing risks for system uptime and reliability. Users of SAP MDM Server are encouraged to apply patches to mitigate these vulnerabilities.

Affected Version(s)

SAP MDM Server MDM_SERVER 710.750

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42995 : Memory Access Violation in SAP MDM Server by SAP