CVE-2025-42897: SAP SE SAP Business One Sld

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal user access could gain access to unauthorized information. As a result, it has a low impact on the confidentiality of the application but no impact on the integrity and availability.

Affected products

  • SAP SE SAP Business One Sld: version B1_ON_HANA 10.0 only

Published 2025-11-11. Last modified 2026-06-17.