The following table lists the changes that have been made to the
CVE-2025-42992 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jul. 08, 2025
Action Type Old Value New Value Added Description SAPCAR allows an attacker logged in with high privileges to create a malicious SAR archive in SAPCAR. This could enable the attacker to exploit critical files and directory permissions without breaking signature validation, resulting in potential privilege escalation. This has high impact on integrity, but low impact on confidentiality and availability of the system. Added CVSS V3.1 AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L Added CWE CWE-266 Added Reference https://me.sap.com/notes/3595143 Added Reference https://url.sap/sapsecuritypatchday