CVE-2025-42970 – SAPCAR Directory Traversal Vulnerability

The following table lists the changes that have been made to the
CVE-2025-42970 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 08, 2025

    Action Type Old Value New Value
    Added Description SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a malicious SAPCAR archive containing directory traversal sequences. When a high privileged victim extracts this malicious archive, it is then processed by SAPCAR on their system, causing files to be extracted outside the intended directory and overwriting files in arbitrary locations. This vulnerability has a high impact on the integrity and availability of the application with no impact on confidentiality.
    Added CVSS V3.1 AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
    Added CWE CWE-22
    Added Reference https://me.sap.com/notes/3595156
    Added Reference https://url.sap/sapsecuritypatchday
Share the Post:

Related Posts