CVE-2025-42947 – SAP FICA ODN Framework Remote Code Execution

The following table lists the changes that have been made to the
CVE-2025-42947 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 23, 2025

    Action Type Old Value New Value
    Added Description SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.
    Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
    Added CWE CWE-94
    Added Reference https://me.sap.com/notes/3540688
    Added Reference https://url.sap/sapsecuritypatchday
Share the Post:

Related Posts