CVE-2025-42982 PUBLISHED

Information Disclosure in SAP GRC (AC Plugin)

Assigner: sap
Reserved: 16.04.2025 Published: 10.06.2025 Updated: 12.06.2025

SAP GRC allows a non-administrative user to access and initiate transaction which could allow them to modify or control the transmitted system credentials. This causes high impact on confidentiality, integrity and availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor SAP_SE
Product SAP GRC (AC Plugin)
Versions Default: unaffected
  • Version GRCPINW V1100_700 is affected
  • Version V1100_731 is affected

References

Problem Types