CVE-2025-42930
MEDIUMDescription
SAP Business Planning and Consolidation allows an authenticated standard user to call a function module by crafting specific parameters that causes a loop, consuming excessive resources and resulting in system unavailability. This leads to high impact on the availability of the application, there is no impact on confidentiality or integrity.
Is your site exposed to CVE-2025-42930?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2025-42930? +
How severe is CVE-2025-42930? +
How do I check if I'm vulnerable to CVE-2025-42930? +
Related Vulnerabilities
smol-toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7.1, parse() can enter an infinite loop …
Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with …
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and …
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive …
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, …
GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the …