CVE-2025-42912: SAP SE SAP Hcm My Timesheet Fiori 2.0 Application

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

Affected products

  • SAP SE SAP Hcm My Timesheet Fiori 2.0 Application

Published 2025-09-09. Last modified 2026-06-17.