CVE-2025-42907: SAP SE SAP BI Platform

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system.

Affected products

  • SAP SE SAP BI Platform: version 2025 only; version 2027 only

Published 2025-09-23. Last modified 2026-06-17.