The following table lists the changes that have been made to the
CVE-2025-43001 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jul. 08, 2025
Action Type Old Value New Value Added Description SAPCAR allows an attacker logged in with high privileges to override the permissions of the current and parent directories of the user or process extracting the archive, leading to privilege escalation. On successful exploitation, an attacker could modify the critical files by tampering with signed archives without breaking the signature, but it has a low impact on the confidentiality and availability of the system. Added CVSS V3.1 AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L Added CWE CWE-266 Added Reference https://me.sap.com/notes/3595143 Added Reference https://url.sap/sapsecuritypatchday