CVE-2025-42909: Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances
SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42909?
CVE-2025-42909 has a low severity level, primarily impacting confidentiality due to the insecure default profile settings.
How do I fix CVE-2025-42909?
To fix CVE-2025-42909, administrators should review the default profile settings in SAP Cloud Appliance Library and modify them to adhere to security best practices.
Who is affected by CVE-2025-42909?
CVE-2025-42909 affects users of SAP Cloud Appliance Library that utilize the default S/4HANA profile settings.
What are the potential impacts of CVE-2025-42909?
The potential impacts of CVE-2025-42909 include unauthorized access to other appliances within the same SAP Cloud environment.
Is there a patch for CVE-2025-42909?
Yes, SAP recommends applying specific security notes and guidelines to mitigate the risks associated with CVE-2025-42909.