CVE-2025-43009: SAP SE SAP Service Parts Management Spm
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.
Affected products
- SAP SE SAP Service Parts Management Spm: version 602 only; version 603 only; version 604 only; version 605 only; version 606 only; version 616 only; …
Published 2025-05-13. Last modified 2026-06-17.