CVE-2025-42998: SAP SE SAP Business One Integration Framework

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The security settings in the SAP Business One Integration Framework are not adequately checked, allowing attackers to bypass the 403 Forbidden error and access restricted pages. This leads to low impact on confidentiality of the application, there is no impact on integrity and availability.

Affected products

  • SAP SE SAP Business One Integration Framework: version B1_ON_HANA 10.0 only

Published 2025-06-10. Last modified 2026-06-17.