CVE-2025-25241: SAP SE SAP Fiori Apps Reference Library My Overtime Requests

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.

Affected products

  • SAP SE SAP Fiori Apps Reference Library My Overtime Requests

Published 2025-02-11. Last modified 2026-06-17.