CVE-2025-42996
Published: 10 June 2025
Summary
CVE-2025-42996 is a medium-severity Free of Memory not on the Heap (CWE-590) vulnerability in Sap (inferred from references). Its CVSS base score is 5.6 (Medium).
Operationally, ranked at the 49.1th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-17593
Vulnerability details
SAP MDM Server allows an attacker to gain control of existing client sessions and execute certain functions without having to re-authenticate giving the ability to access or modify non-sensitive information or consume sufficient resources which could degrade the performance of…
more
the server causing low impact on confidentiality, integrity and availibility of the application.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.