Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access customer data when they access these dashboards. Since no mechanisms exist to enforce authentication, malicious unauthenticated users can view non-sensitive customer information. However, this does not affect data integrity or availability.
History

Tue, 13 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 00:45:00 +0000

Type Values Removed Values Added
Description Due to a security misconfiguration vulnerability, customers can develop Production Operator Dashboards (PODs) that enable outside users to access customer data when they access these dashboards. Since no mechanisms exist to enforce authentication, malicious unauthenticated users can view non-sensitive customer information. However, this does not affect data integrity or availability.
Title Security Misconfiguration Vulnerability in SAP Digital Manufacturing (Production Operator Dashboard)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-05-13T00:18:35.364Z

Updated: 2025-05-13T14:01:59.045Z

Reserved: 2025-04-16T13:25:53.589Z

Link: CVE-2025-43004

cve-icon Vulnrichment

Updated: 2025-05-13T14:01:56.255Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T01:15:49.020

Modified: 2025-05-13T19:35:18.080

Link: CVE-2025-43004

cve-icon Redhat

No data.