CVE-2025-43007: SAP SE SAP Service Parts Management Spm

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on confidentiality, integrity and availability of the application.

Affected products

  • SAP SE SAP Service Parts Management Spm: version 618 only; version S4CORE 100 only; version 101 only; version 102 only; version 103 only

Published 2025-05-13. Last modified 2026-06-17.