CVE-2025-42876: Missing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)
Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42876?
CVE-2025-42876 is considered a high severity vulnerability due to the potential for unauthorized access and data manipulation.
How do I fix CVE-2025-42876?
To fix CVE-2025-42876, apply the latest security patches provided by SAP for S/4 HANA Private Cloud.
What type of threat does CVE-2025-42876 present?
CVE-2025-42876 presents a threat of unauthorized data access and modification by an authenticated user with limited permissions.
Who is affected by CVE-2025-42876?
CVE-2025-42876 affects organizations using SAP S/4 HANA Private Cloud, particularly in financial management.
What should I do if my system is vulnerable to CVE-2025-42876?
If your system is vulnerable to CVE-2025-42876, it is essential to immediately apply the relevant SAP security updates and review access controls.