CVE-2025-25241: SAP SE SAP Fiori Apps Reference Library My Overtime Requests
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.
Affected products
- SAP SE SAP Fiori Apps Reference Library My Overtime Requests
Published 2025-02-11. Last modified 2026-06-17.