CRITICAL

CVE-2025-42937

2025-10-14 CVSS v3.1
CVSS
9.8

Description

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the application.

Summary dbcve.org

SAP Print Service (SAPSprint) contains a path traversal vulnerability due to insufficient validation of user-supplied path information. An unauthenticated attacker can use directory traversal sequences (e.g., ../../) to escape the intended directory and overwrite arbitrary system files on the host, achieving full compromise of confidentiality, integrity, and availability.

Mitigation

Apply the SAP security patch for CVE-2025-42937 immediately. As an interim measure, restrict network access to SAPSprint ports and implement web application firewall rules to block path traversal patterns.

Weakness (CWE)

CWE-35

EPSS Score

0.74%
Probability of exploitation in next 30 days
53.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE