CVE-2025-42916: SAP SE SAP s/4hana Private Cloud Or On-Premise

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.

Affected products

  • SAP SE SAP s/4hana Private Cloud Or On-Premise: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only; version 107 only; …

Published 2025-09-09. Last modified 2026-09-30.