VYPR
Medium severity6.5NVD Advisory· Published Sep 9, 2025· Updated Apr 15, 2026

CVE-2025-42917

CVE-2025-42917

Description

SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SAP HCM Approve Timesheets Fiori 2.0 lacks authorization checks allowing privilege escalation by authenticated users, compromising integrity.

Vulnerability

Overview CVE-2025-42917 is an authorization bypass vulnerability in the SAP HCM Approve Timesheets Fiori 2.0 application. The application fails to perform necessary authorization checks for authenticated users, leading to an escalation of privileges. This flaw primarily impacts the integrity of the application, while confidentiality and availability remain unaffected.

Exploitation

Conditions An authenticated user can exploit this vulnerability by directly accessing functions or data that should require higher privileges. No special network position or additional authentication is required beyond a valid user session. The attack surface is limited to authenticated users within the system.

Impact

Successful exploitation allows an attacker to gain elevated privileges, enabling them to perform unauthorized actions such as approving or modifying timesheet entries beyond their intended scope. This can undermine the trustworthiness of approval workflows and data integrity.

Mitigation

SAP has released a security note addressing this issue as part of its regular Security Patch Day. Users are strongly advised to apply the latest available patch to remediate the vulnerability [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.