Security Flaw in SAP Business One Integration Framework Allows Unauthorized Access
CVE-2025-42998
5.3MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-42998?
A vulnerability in the SAP Business One Integration Framework exists due to insufficient security checks, allowing attackers to bypass standard 403 Forbidden responses. This flaw enables unauthorized access to restricted areas of the application, raising concerns over the potential compromise of sensitive information. While the impact on confidentiality is low, accessing such areas can pose risks associated with information exposure.
Affected Version(s)
SAP Business One Integration Framework B1_ON_HANA 10.0
SAP Business One Integration Framework SAP-M-BO 10.0