CVE-2025-42994: SAP SE SAP Mdm Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

Affected products

Published 2025-06-10. Last modified 2026-06-17.