CVE-2025-43002
MEDIUMDescription
SAP S4CORE OData meta-data property allows an authenticated attacker to access restricted information due to missing authorization check. This could cause a low impact on confidentiality but integrity and availability of the application are not impacted.
Is your site exposed to CVE-2025-43002?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2025-43002? +
How severe is CVE-2025-43002? +
How do I check if I'm vulnerable to CVE-2025-43002? +
Related Vulnerabilities
QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:
FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the …
MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, …
SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter.
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints …
UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such …