CVE-2025-42965 MEDIUM

CVE-2025-42965: Server Side Request Forgery(SSRF) vulnerability in SAP BusinessObjects BI Platform Central Management Console Promotion Management Application

Vendor Sap_Se
Product SAP BusinessObjects BI Platform Central Management Console Promotion Management Application
Weakness CWE-918 · SSRF
Published July 8, 2025
Last update July 11, 2025

CVSS base score

4.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

SAP CMC Promotion Management allows an authenticated attacker to enumerate internal network systems by submitting crafted requests during job source configuration. By analysing response times for various IP addresses and ports, the attacker can infer valid network endpoints. Successful exploitation may lead to information disclosure. This vulnerability does not impact the integrity or availability of the application.

Key dates

02Disclosure timeline

July 8, 2025 CVE published
July 11, 2025 Record updated