Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-42965

Опубликовано: 08 июл. 2025
Источник: nvd
CVSS3: 4.1
EPSS Низкий

Описание

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to information disclosure. This vulnerability does not impact the integrity or availability of the application.

EPSS

Процентиль: 8%
0.0003
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.1
github
7 месяцев назад

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to information disclosure. This vulnerability does not impact the integrity or availability of the application.

CVSS3: 4.1
fstec
7 месяцев назад

Уязвимость веб-инструмента для выполнения задач администрирования SAP BusinessObjects BI Platform Central Management Console, связанная c подделкой запросов на стороне сервера, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 8%
0.0003
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-918