Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Nov 2025 06:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Nov 2025 22:00:00 +0900

Type Values Removed Values Added
First Time appeared Sap
Sap hana-client
Vendors & Products Sap
Sap hana-client

Tue, 11 Nov 2025 09:45:00 +0900

Type Values Removed Values Added
Description Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.
Title Code Injection vulnerability in SAP HANA JDBC Client
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-11-12T20:10:07.123Z

Reserved: 2025-04-16T13:25:22.788Z

Link: CVE-2025-42895

cve-icon Vulnrichment

Updated: 2025-11-12T17:31:41.823Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-11T01:15:38.487

Modified: 2025-11-12T16:19:59.103

Link: CVE-2025-42895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-12T21:47:57Z

Weaknesses