CVE-2025-43003: SAP SE SAP s/4hana Private Cloud & On-Premise

Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP S/4 HANA allows an authenticated attacker with user privileges to configure a field not intended for their access and create a custom UI layout displaying this field. On performing this step the attacker could gain access to highly sensitive information. This could cause a high impact on confidentiality and minimal impact on integrity and availability of the application.

Affected products

  • SAP SE SAP s/4hana Private Cloud & On-Premise: version S4CRM 204 only; version 205 only; version 206 only; version S4CEXT 107 only; version 108 only; version 712 only; …

Published 2025-05-13. Last modified 2026-06-17.