CVE-2025-43001 – SAPCAR Privilege Escalation Directory Traversal

The following table lists the changes that have been made to the
CVE-2025-43001 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 08, 2025

    Action Type Old Value New Value
    Added Description SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system.
    Added CVSS V3.1 AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L
    Added CWE CWE-266
    Added Reference https://me.sap.com/notes/3595143
    Added Reference https://url.sap/sapsecuritypatchday
Share the Post:

Related Posts