CVE-2025-42995 Details
Description
SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read access violation in the server process that would then fail and exit unexpectedly causing high impact on availability with no impact on confidentiality and integrity of the application.
A vulnerability in the SAP MDM Server Read function allows an attacker to send specially crafted packets that can cause a memory read access violation. This violation leads to the server process failing and exiting unexpectedly, creating a significant denial-of-service condition. While this issue severely impacts the application's availability, it does not affect its confidentiality or integrity.
Users are advised to review and implement the SAP Security Note related to this vulnerability. This can be done through the SAP for Me platform, specifically in the Security Notes section. For guidance on accessing and applying SAP Security Notes, refer to the SAP Security Notes FAQs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 10, 2025CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://me.sap.com/notes/3610006 | [email protected] | Permission RequiredVendor |
| https://url.sap/sapsecuritypatchday | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-590 | Free of Memory not on the Heap | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SAP MDM Server | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2025 | New CVE Received | [email protected] |
Volerion