CVE-2025-42913: Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability are not impacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42913?
CVE-2025-42913 has a low severity impact on the integrity of the SAP HCM My Timesheet Fiori 2.0 application.
How do I fix CVE-2025-42913?
To fix CVE-2025-42913, ensure that proper authorization checks are implemented in the application's access control mechanisms.
What type of attack does CVE-2025-42913 facilitate?
CVE-2025-42913 can facilitate privilege escalation attacks by authenticated users with deep system knowledge.
Who is affected by CVE-2025-42913?
CVE-2025-42913 affects users of the SAP HCM My Timesheet Fiori 2.0 application.
What causes the vulnerability CVE-2025-42913?
CVE-2025-42913 is caused by missing authorization checks within the SAP HCM My Timesheet Fiori application.