VDB
CISA-2025-42909
CISA-2025-42909
PUBLISHED
CVSS 3 LOW
Reported by sap · Published October 14, 2025
SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.
Risk Scores
CVSS 3.1
3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP Cloud Appliance Library Appliances | TITANIUM_WEBAPP 4.0 |
| SAP_SE | SAP Cloud Appliance Library Appliances | TITANIUM_WEBAPP 4.0, TITANIUM_WEBAPP 4.0 |
Timeline
- Oct 14, 2025 CVE Published
- Oct 14, 2025 CVE Updated