CVE-2025-31333: SAP SE SAP s4core Entity

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP S4CORE OData meta-data property is vulnerable to data tampering, due to which entity set could be externally modified by an attacker causing low impact on integrity of the application. Confidentiality and availability is not impacted.

Affected products

  • SAP SE SAP s4core Entity: version S4CORE 107 only; version 108 only

Published 2025-04-08. Last modified 2026-06-17.