The following table lists the changes that have been made to the
CVE-2025-42971 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jul. 08, 2025
Action Type Old Value New Value Added Description A memory corruption vulnerability exists in SAPCAR allowing an attacker to craft malicious SAPCAR archives. When a high privileged victim extracts this malicious archive, it gets processed by SAPCAR on their system, resulting in out-of-bounds memory read and write. This could lead to file extraction and file overwrite outside the intended directories. This vulnerability has low impact on the confidentiality, integrity and availability of the application. Added CVSS V3.1 AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L Added CWE CWE-787 Added Reference https://me.sap.com/notes/3595141 Added Reference https://url.sap/sapsecuritypatchday