CVE-2025-42955 describes a missing authorization check in SAP Cloud Connector, allowing a low-privileged attacker on an adjacent network to send a crafted request to the LDAP connection test endpoint. This vulnerability carries a low severity CVSS score of 3.5, as it primarily impacts availability through reduced performance, with no effect on data confidentiality or integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP Cloud Connector | SAP_CLOUD_CONNECTOR 2.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.