CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-42994: Multiple vulnerabilities in SAP MDM Server

7.5 CVSS

Description

SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.

Classification

CVE ID: CVE-2025-42994

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem Types

CWE-590: Free of Memory not on the Heap

Affected Products

Vendor: SAP_SE

Product: SAP MDM Server

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 8.21% (scored less or equal to compared to others)

EPSS Date: 2025-06-13 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-42994
https://me.sap.com/notes/3610006
https://url.sap/sapsecuritypatchday

Timeline