CVE-2025-42952: SAP SE SAP Business Warehouse And SAP Plug-In Basis

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP Business Warehouse and SAP Plug-In Basis allows an authenticated attacker to add fields to arbitrary SAP database tables and/or structures, potentially rendering the system unusable. On successful exploitation, an attacker can render the system unusable by triggering short dumps on login. This could cause a high impact on availability. Data confidentiality and integrity are not affected. No data can be read, changed or deleted.

Affected products

  • SAP SE SAP Business Warehouse And SAP Plug-In Basis: version 701 only; version 702 only; version 731 only; version 740 only; version 750 only; version 751 only; …

Published 2025-07-08. Last modified 2026-06-17.