---
id: CVE-2025-42916
title: >-
  Due to missing input validation, an attacker with high privilege access to
  ABAP reports could delete the content of arbitrary database tables, if the
  tables are not protected by an authorization group
summary: >-
  Due to missing input validation, an attacker with high privilege access to
  ABAP reports could delete the content of arbitrary database tables, if the
  tables are not protected by an authorization group. This leads to a high
  impact on inte…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H'
cwe:
  - CWE-1287
published: '2025-09-09'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42916'
references:
  - url: 'https://me.sap.com/notes/3635475'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00267
epssPercentile: 0.16994
ingestedAt: '2026-09-30T23:29:32.374Z'
---

## Overview

Due to missing input validation, an attacker with high privilege access to ABAP reports could delete the content of arbitrary database tables, if the tables are not protected by an authorization group. This leads to a high impact on integrity and availability of the database but no impact on confidentiality.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
