CVE-2025-43002: SAP SE SAP s4/hana Odata Meta-Data Property

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted.

Affected products

  • SAP SE SAP s4/hana Odata Meta-Data Property: version S4CORE 102 only; version 103 only; version 104 only; version 105 only; version 106 only

Published 2025-05-13. Last modified 2026-06-17.