CVE-2025-42910: Unrestricted File Upload Vulnerability in SAP Supplier Relationship Management
Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause high impact on confidentiality, integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42910?
CVE-2025-42910 has been classified with a high severity level due to its potential to allow unauthorized file uploads.
How do I fix CVE-2025-42910?
Fixing CVE-2025-42910 involves applying patches provided by SAP that address the file upload vulnerability.
What are the risks associated with CVE-2025-42910?
The risks of CVE-2025-42910 include the potential for uploading and executing malicious files, leading to data breaches or system compromise.
Who is affected by CVE-2025-42910?
All users of SAP Supplier Relationship Management are potentially affected by CVE-2025-42910 if they do not secure the file upload functionality.
What actions should be taken to mitigate CVE-2025-42910?
To mitigate CVE-2025-42910, organizations should implement strict file type validation and content checks on uploads.