CVE-2025-42929
8.1SAP · Landscape Transformation Replication Server
A lack of input validation in SAP Landscape Transformation Replication Server allows high privilege users to delete data from unprotected database tables.
Executive summary
An authenticated attacker with high privileges can cause significant data loss in SAP Landscape Transformation Replication Server by deleting content from unprotected database tables.
Vulnerability
The flaw involves improper validation of input within ABAP reports (CWE-1287). An attacker possessing high-level access can leverage this to execute unauthorized deletions against database tables that lack specific authorization group protections.
Business impact
The ability to delete arbitrary database content poses a critical threat to data integrity and system availability. With a CVSS score of 8.1, the vulnerability is classified as High severity, as it could result in the destruction of vital business records or the disruption of core enterprise processes.
Remediation
Immediate Action: Consult SAP Security Note 3633002 to identify and apply the necessary security updates or configuration changes for your specific DMIS version.
Proactive Monitoring: Review SAP system logs for unusual execution of administrative ABAP reports or unexpected database modification operations.
Compensating Controls: Ensure that sensitive database tables are assigned to appropriate authorization groups to restrict access and prevent unauthorized modifications by high-privileged accounts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for significant data loss, organizations should prioritize the review of SAP Security Note 3633002. Administrators must ensure that access to sensitive database tables is strictly governed and that all relevant patches are deployed to mitigate the risk of unauthorized data deletion.