CVE-2025-43011
Last modified
CVE-2025-43011 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the integrity or availability of the application.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Under certain conditions, SAP Landscape Transformation's PCL Basis module does not perform the necessary authorization checks, allowing authenticated users to access restricted functionalities or data. This can lead to a high impact on confidentiality with no impact on the integrity or availability of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-43011?
How severe is CVE-2025-43011?
How do I fix CVE-2025-43011?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-43006SAP Supplier Relationship Management (Master Data Management…6.1
- CVE-2025-43007SAP Service Parts Management (SPM) does not perform necessar…6.3
- CVE-2025-43008Due to missing authorization check, an unauthorized user can…5.8
- CVE-2025-43009SAP Service Parts Management (SPM) does not perform necessar…6.3
- CVE-2025-4301A vulnerability classified as critical was found in itsource…9.8
- CVE-2025-43010SAP S/4HANA Cloud Private Edition or on Premise (SCM Master …8.3
- CVE-2025-43012In JetBrains Toolbox App before 2.6 command injection in SSH…9.8
- CVE-2025-43013In JetBrains Toolbox App before 2.6 unencrypted credential t…7.5
- CVE-2025-43014In JetBrains Toolbox App before 2.6 the SSH plugin establish…6.5
- CVE-2025-43015In JetBrains RubyMine before 2025.1 remote Interpreter overw…6.5
- CVE-2025-43016In JetBrains Rider before 2025.1.2 custom archive unpacker a…7.5
- CVE-2025-43017HP ThinPro 8.1 System management application failed to verif…9.8
Are you affected by CVE-2025-43011?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
