Authorization Flaw in SAP Product Results in Data Exposure
CVE-2025-43008

5.8MEDIUM

What is CVE-2025-43008?

An authorization check flaw within SAP's application allows unauthorized users to access files belonging to other companies. This can lead to the exposure of sensitive employee personal data. While the integrity and availability of the system are unaffected, the potential for privacy violations necessitates urgent remediation.

Affected Version(s)

SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal S4HCMCPT 100

SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal 101

SAP S/4HANA HCM Portugal and SAP ERP HCM Portugal SAP_HRCPT 600

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

.