CVE-2025-42955: Missing authorization check in SAP Cloud Connector
Due to a missing authorization check in SAP Cloud Connector, an attacker on an adjacent network with low privileges could send a crafted request to the endpoint responsible for testing LDAP connections. A successful exploit could lead to reduced performance, hence a low-impact on availability of the service. Confidentiality and integrity of the data are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42955?
CVE-2025-42955 is classified as low severity due to its low impact on availability and performance.
How do I fix CVE-2025-42955?
To remediate CVE-2025-42955, ensure that proper authorization checks are implemented for the SAP Cloud Connector.
What software is affected by CVE-2025-42955?
CVE-2025-42955 affects the SAP Cloud Connector.
Can CVE-2025-42955 be exploited remotely?
Yes, CVE-2025-42955 can be exploited by attackers on an adjacent network with low privileges.
What is the potential impact of CVE-2025-42955?
The exploitation of CVE-2025-42955 could lead to reduced performance of the SAP Cloud Connector.