CVE-2025-42946
Last modified
CVE-2025-42946 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attacker to potentially read or delete these files hence causing a high impact on confidentiality and low impact on integrity. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific transaction and method in Bank Communication Management could gain unauthorized access to sensitive operating system files. This could allow the attacker to potentially read or delete these files hence causing a high impact on confidentiality and low impact on integrity. There is no impact on availability of the system.
Metrics
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-42946?
How severe is CVE-2025-42946?
How do I fix CVE-2025-42946?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-42940SAP CommonCryptoLib does not perform necessary boundary chec…7.5
- CVE-2025-42941SAP Fiori (Launchpad) is vulnerable to Reverse Tabnabbing vu…3.5
- CVE-2025-42942SAP NetWeaver Application Server for ABAP has cross-site scr…6.1
- CVE-2025-42943SAP GUI for Windows may allow the leak of NTML hashes when s…4.5
- CVE-2025-42944Due to a deserialization vulnerability in SAP NetWeaver, an …10
- CVE-2025-42945SAP NetWeaver Application Server ABAP has HTML injection vul…6.1
- CVE-2025-42947SAP FICA ODN framework allows a high privileged user to inje…5.5
- CVE-2025-42948Due to a Cross-Site Scripting (XSS) vulnerability in SAP Net…6.1
- CVE-2025-42949Due to a missing authorization check in the ABAP Platform, a…4.9
- CVE-2025-4295Improper Validation of Certificate with Host Mismatch vulner…4.6
- CVE-2025-42950SAP Landscape Transformation (SLT) allows an attacker with u…9.9
- CVE-2025-42951Due to broken authorization, SAP Business One (SLD) allows a…8.8
Are you affected by CVE-2025-42946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
