CVE-2025-42910

Published Oct 14, 2025

Last updated 4 months ago

Overview

Description
Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause high impact on confidentiality, integrity and availability of the application.
Source
cna@sap.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9
Impact score
6
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-434

Social media

Hype score
Not currently trending
  1. CVE-2025-42910 (CVSS:9.0, CRITICAL) is Awaiting Analysis. Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attack..https://t.co/XSTEjWkZdK #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    19 Oct 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-42910 – Critical Unrestricted File Upload Vulnerability in SAP SRM https://t.co/TLQJwcOOwV #patchmanagement

    @eyalestrin

    15 Oct 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-42910 – Critical Unrestricted File Upload Vulnerability in SAP SRM https://t.co/gbhKups1Jv

    @Dinosn

    14 Oct 2025

    2033 Impressions

    4 Retweets

    8 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  4. Critical Unrestricted File Upload in SAP SRM (CVE-2025-42910) Attackers can upload malicious files, leading to full system compromise. Patch ASAP. For more details, read ZeroPath's blog on this vuln. #SAP #AppSec #InfoSec https://t.co/TIWSSI1mUJ

    @ZeroPathLabs

    14 Oct 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. **CVE-2025-42910** pertains to a security flaw in SAP Supplier Relationship Management (SAP SRM) where the system fails to properly verify the type or content of uploaded files. This oversight allows an authenticated attacker to upload arbitrary files, including potentially

    @CveTodo

    14 Oct 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-42910 Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files coul… https://t.co/40dXec7XT4

    @CVEnew

    14 Oct 2025

    364 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-42910: CRITICAL] SAP Supplier Relationship Management vulnerability allows attackers to upload malicious files, risking malware infection and jeopardizing data security and system availability.#cve,CVE-2025-42910,#cybersecurity https://t.co/QdtaPilGu7 https://t.co/WmQuC

    @CveFindCom

    14 Oct 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.