---
id: CVE-2025-42909
title: >-
  SAP Cloud Appliance Library Appliances allows an attacker with high privileges
  to leverage an insecure S/4HANA default profile setting in an existing SAP CAL
  appliances to gain access to other appliances
summary: >-
  SAP Cloud Appliance Library Appliances allows an attacker with high privileges
  to leverage an insecure S/4HANA default profile setting in an existing SAP CAL
  appliances to gain access to other appliances. This has low impact on
  confident…
severity: low
cvss: 3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-1004
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42909'
references:
  - url: 'https://me.sap.com/notes/3643871'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00242
epssPercentile: 0.14089
ingestedAt: '2026-10-08T11:31:27.364Z'
---

## Overview

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain access to other appliances. This has low impact on confidentiality of the application, integrity and availability is not impacted.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
