CVE-2025-42923
Description
Due to insufficient CSRF protection in SAP Fiori App Manage Work Center Groups, an authenticated user could be tricked by an attacker to send unintended request to the web server. This has low impact on integrity and no impact on confidentiality and availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
SAP Fiori App Manage Work Center Groups has insufficient CSRF protection, enabling authenticated users to be tricked into executing unintended requests with low integrity impact.
Vulnerability
Description
CVE-2025-42923 describes a cross-site request forgery (CSRF) vulnerability in the SAP Fiori App Manage Work Center Groups. The application fails to implement adequate CSRF protection mechanisms, such as anti-CSRF tokens or proper validation of request origins, allowing an attacker to induce an authenticated user to perform unintended actions on the web server.
Exploitation
Conditions
To exploit this vulnerability, an attacker must trick an authenticated user into interacting with a malicious link or visiting a crafted webpage while logged into the application. No additional privileges are required beyond the user's existing session. The attack can be performed remotely over the network, but it relies on social engineering to succeed.
Impact
Successful exploitation has a low impact on integrity, meaning an attacker could modify data or settings within the Manage Work Center Groups function. There is no impact on confidentiality or availability of the application. The CVSS v3 base score is 4.3 (Medium), reflecting the limited consequences and the need for user interaction.
Mitigation
SAP has addressed this vulnerability in their monthly Security Patch Day releases. Organizations should apply the relevant SAP Security Notes as recommended by SAP [1]. No workarounds are currently available, so updating to the patched version is the primary mitigation.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.