An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00067}

epss

{'score': 0.0008}


Tue, 08 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Jul 2025 00:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker may exploit a scenario where a Hashed Message Authentication Code (HMAC) credential, extracted from a system missing specific security patches, is reused in a replay attack against a different system. Even if the target system is fully patched, successful exploitation could result in complete system compromise, affecting confidentiality, integrity, and availability.
Title Missing Authentication check after implementation of SAP Security Note 3007182 and 3537476
Weaknesses CWE-308
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-07-08T00:35:03.181Z

Updated: 2025-07-11T03:55:25.728Z

Reserved: 2025-04-16T13:25:39.584Z

Link: CVE-2025-42959

cve-icon Vulnrichment

Updated: 2025-07-08T14:31:06.483Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-08T01:15:22.477

Modified: 2025-07-08T16:18:14.207

Link: CVE-2025-42959

cve-icon Redhat

No data.