- Description
- Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause high impact on confidentiality, integrity and availability of the application.
- Source
- cna@sap.com
- NVD status
- Deferred
CVSS 3.1
- Type
- Secondary
- Base score
- 9
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- cna@sap.com
- CWE-434
- Hype score
- Not currently trending
CVE-2025-42910 (CVSS:9.0, CRITICAL) is Awaiting Analysis. Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attack..https://t.co/XSTEjWkZdK #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
19 Oct 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-42910 – Critical Unrestricted File Upload Vulnerability in SAP SRM https://t.co/TLQJwcOOwV #patchmanagement
@eyalestrin
15 Oct 2025
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-42910 – Critical Unrestricted File Upload Vulnerability in SAP SRM https://t.co/gbhKups1Jv
@Dinosn
14 Oct 2025
2033 Impressions
4 Retweets
8 Likes
2 Bookmarks
0 Replies
0 Quotes
Critical Unrestricted File Upload in SAP SRM (CVE-2025-42910) Attackers can upload malicious files, leading to full system compromise. Patch ASAP. For more details, read ZeroPath's blog on this vuln. #SAP #AppSec #InfoSec https://t.co/TIWSSI1mUJ
@ZeroPathLabs
14 Oct 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
**CVE-2025-42910** pertains to a security flaw in SAP Supplier Relationship Management (SAP SRM) where the system fails to properly verify the type or content of uploaded files. This oversight allows an authenticated attacker to upload arbitrary files, including potentially
@CveTodo
14 Oct 2025
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-42910 Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files coul… https://t.co/40dXec7XT4
@CVEnew
14 Oct 2025
364 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-42910: CRITICAL] SAP Supplier Relationship Management vulnerability allows attackers to upload malicious files, risking malware infection and jeopardizing data security and system availability.#cve,CVE-2025-42910,#cybersecurity https://t.co/QdtaPilGu7 https://t.co/WmQuC
@CveFindCom
14 Oct 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes