CVE-2025-42951: Broken Authorization in SAP Business One (SLD)
Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42951?
CVE-2025-42951 has a high severity level due to its potential for unauthorized access and privilege escalation.
How can I fix CVE-2025-42951?
To fix CVE-2025-42951, apply the latest security patches provided by SAP for Business One.
What type of attack does CVE-2025-42951 enable?
CVE-2025-42951 enables an authenticated attacker to gain administrator privileges through a specific API call.
Who is affected by CVE-2025-42951?
Organizations using SAP Business One are affected by CVE-2025-42951 regarding their database security.
What impact does CVE-2025-42951 have on SAP Business One?
CVE-2025-42951 impacts the confidentiality, integrity, and availability of SAP Business One, leading to potential data breaches.