CVE-2025-42951: SAP SE SAP Business One Sld

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Due to broken authorization, SAP Business One (SLD) allows an authenticated attacker to gain administrator privileges of a database by invoking the corresponding API.�As a result , it has a high impact on the confidentiality, integrity, and availability of the application.

Affected products

  • SAP SE SAP Business One Sld: version B1_ON_HANA 10.0 only

Published 2025-08-12. Last modified 2026-06-17.