CVE-2025-42907
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
23/09/2025
Last modified:
24/09/2025
Description
SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system.
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM



