VDB

CISA-2025-42909

CISA-2025-42909 PUBLISHED CVSS 3 LOW

Reported by sap · Published October 14, 2025

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.

Risk Scores

CVSS 3.1
3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersions
SAP_SESAP Cloud Appliance Library AppliancesTITANIUM_WEBAPP 4.0
SAP_SESAP Cloud Appliance Library AppliancesTITANIUM_WEBAPP 4.0, TITANIUM_WEBAPP 4.0

Timeline

  • Oct 14, 2025 CVE Published
  • Oct 14, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›