Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.
History

Wed, 12 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap hana-client
Vendors & Products Sap
Sap hana-client

Tue, 11 Nov 2025 00:45:00 +0000

Type Values Removed Values Added
Description Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.
Title Code Injection vulnerability in SAP HANA JDBC Client
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-11-11T00:19:38.409Z

Updated: 2025-11-12T20:10:07.123Z

Reserved: 2025-04-16T13:25:22.788Z

Link: CVE-2025-42895

cve-icon Vulnrichment

Updated: 2025-11-12T17:31:41.823Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T01:15:38.487

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-42895

cve-icon Redhat

No data.