CVE-2025-42914: Missing Authorization check in SAP HCM (My Timesheet Fiori 2.0 application)
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability are not impacted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42914?
CVE-2025-42914 is classified as having a low impact on the integrity of the application.
How do I fix CVE-2025-42914?
To fix CVE-2025-42914, it is recommended to apply the latest security patches provided by SAP for the HCM My Timesheet Fiori application.
Who is affected by CVE-2025-42914?
CVE-2025-42914 affects authenticated users of the SAP HCM My Timesheet Fiori 2.0 application.
What type of vulnerability is CVE-2025-42914?
CVE-2025-42914 is a privilege escalation vulnerability due to missing authorization checks.
What can an attacker do with CVE-2025-42914?
An attacker with in-depth system knowledge can perform activities that are otherwise restricted within the application.