← Back

CVE-2025-43009

nvd nist
Published: May 13, 2025Modified: Jun 17, 2026Deferred

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitability: 2.8 / Impact: 3.4
Source: CNA (Secondary)

Description

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.

References (2)

Timeline

No history available yet.