CVE-2025-42907

SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system.
Configurations

No configuration.

History

No history.

Information

Published : 2025-09-23 02:15

Updated : 2025-09-24 18:11


NVD link : CVE-2025-42907

Mitre link : CVE-2025-42907

CVE.ORG link : CVE-2025-42907


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)