CVE-2025-25241 Information

Description

Due to a missing authorization check an attacker who is logged in to application can view/ delete ?My Overtime Requests? which could allow the attacker to access employee information. This leads to low impact on confidentiality integrity of the application. There is no impact on availability.

Reference

https://me.sap.com/notes/3532025 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday

Share on: