// For flags

CVE-2025-30016

Authentication Bypass Vulnerability in SAP Financial Consolidation

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.

SAP Financial Consolidation permite que un atacante no autenticado obtenga acceso no autorizado a la cuenta de administrador. La vulnerabilidad surge debido a mecanismos de autenticación inadecuados, lo que afecta gravemente la confidencialidad, la integridad y la disponibilidad de la aplicación.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2025-03-13 CVE Reserved
  • 2025-04-08 CVE Published
  • 2025-04-10 CVE Updated
  • 2025-04-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-921: Storage of Sensitive Data in a Mechanism without Access Control
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
SAP SE
Search vendor "SAP SE"
SAP Financial Consolidation
Search vendor "SAP SE" for product "SAP Financial Consolidation"
1010
Search vendor "SAP SE" for product "SAP Financial Consolidation" and version "1010"
en
Affected