CVE-2025-42906: Directory Traversal vulnerability in SAP Commerce Cloud
SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass configured access restrictions, resulting in a low impact on confidentiality, with no impact on the integrity or availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42906?
CVE-2025-42906 is classified as a critical severity vulnerability due to its potential to allow unauthorized access to sensitive applications.
How do I fix CVE-2025-42906?
To fix CVE-2025-42906, apply the latest security patches provided by SAP for the SAP Commerce Cloud.
What type of vulnerability is CVE-2025-42906?
CVE-2025-42906 is a path traversal vulnerability that enables unauthorized access to restricted resources.
Who is affected by CVE-2025-42906?
CVE-2025-42906 affects installations of SAP Commerce Cloud that do not properly restrict access to the Administration Console.
What consequences could result from CVE-2025-42906?
The consequences of CVE-2025-42906 include potential data breaches and unauthorized access to administrative functions within the application.