Security Flaw in SAP Business One Integration Framework Allows Unauthorized Access
CVE-2025-42998
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-42998?
A vulnerability in the SAP Business One Integration Framework exists due to insufficient security checks, allowing attackers to bypass standard 403 Forbidden responses. This flaw enables unauthorized access to restricted areas of the application, raising concerns over the potential compromise of sensitive information. While the impact on confidentiality is low, accessing such areas can pose risks associated with information exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Business One Integration Framework B1_ON_HANA 10.0
SAP Business One Integration Framework SAP-M-BO 10.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved