Threats Tagged 'cve-2025-42909'
View all threats tagged with 'cve-2025-42909'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-42909'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-42909 is a low-severity vulnerability in SAP Cloud Appliance Library Appliances, specifically affecting the TITANIUM_WEBAPP 4.0 version. It involves a sensitive cookie lacking the HttpOnly flag due to an insecure default profile setting in S/4HANA appliances. An attacker with high privileges on one appliance could potentially access other appliances by exploiting this cookie vulnerability. The impact on confidentiality is low, and there is no impact on integrity or availability. Exploitation requires network access, high privileges, and no user interaction. No known exploits are currently reported in the wild. European organizations using SAP CAL appliances should review and harden their cookie security settings to mitigate risk. Countries with significant SAP enterprise deployments and critical infrastructure relying on SAP systems are more likely to be affected. Join the discussion | CVE Database V5 | 10/14/2025, 00:18:11 UTC Added: 10/14/2025, 00:50:02 UTC |
Showing 1 to 1 of 1 result