---
id: CVE-2025-42910
title: >-
  Due to missing verification of file type or content, SAP Supplier Relationship
  Management allows an authenticated attacker to upload arbitrary files
summary: >-
  Due to missing verification of file type or content, SAP Supplier Relationship
  Management allows an authenticated attacker to upload arbitrary files. These
  files could include executables which might be downloaded and executed by the
  use…
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-434
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42910'
references:
  - url: 'https://me.sap.com/notes/3647332'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00479
epssPercentile: 0.39355
ingestedAt: '2026-10-08T11:31:27.364Z'
---

## Overview

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the user which could host malware. On successful exploitation an attacker could cause high impact on confidentiality, integrity and availability of the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
