CVE-2025-42930
MEDIUMDescription
SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive resources and resulting in system unavailability. This leads to high impact on the availability of the application, there is no impact on confidentiality or integrity.
Is your site exposed to CVE-2025-42930?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2025-42930? +
How severe is CVE-2025-42930? +
How do I check if I'm vulnerable to CVE-2025-42930? +
Related Vulnerabilities
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive …
A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attacker in a …
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and …
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the …
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive …
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS …