CVE-2025-42910: Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management

Published Oct 14, 2025
·
Updated

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause high impact on confidentiality, integrity and availability of the application.

Affected Software

1 affected component
SAP Supplier Relationship Management

Event History

Oct 14, 2025
CVE Published
via MITRE·12:18 AM
Data Sourced
via MITRE·12:18 AM
DescriptionSeverity
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-42910?

CVE-2025-42910 has been classified with a high severity level due to its potential to allow unauthorized file uploads.

2

How do I fix CVE-2025-42910?

Fixing CVE-2025-42910 involves applying patches provided by SAP that address the file upload vulnerability.

3

What are the risks associated with CVE-2025-42910?

The risks of CVE-2025-42910 include the potential for uploading and executing malicious files, leading to data breaches or system compromise.

4

Who is affected by CVE-2025-42910?

All users of SAP Supplier Relationship Management are potentially affected by CVE-2025-42910 if they do not secure the file upload functionality.

5

What actions should be taken to mitigate CVE-2025-42910?

To mitigate CVE-2025-42910, organizations should implement strict file type validation and content checks on uploads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203