CVE-2025-42897 is an information disclosure vulnerability in the anonymous API of SAP Business One (SLD). An attacker with normal user access could exploit this to gain unauthorized information, though the impact on confidentiality is low, and there is no impact on integrity or availability. With a CVSS score of 5.3 (Medium), it requires no user interaction and has low attack complexity, but only affects confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP Business One (SLD) | B1_ON_HANA 10.0, SAP-M-BO 10.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.