Advisory
On 08.07.2025 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAPCAR.
SAP Note 3595141 addresses "[CVE-2025-42971] Memory Corruption vulnerability in SAPCAR" to prevent memory corruption with a medium risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process, the team suggests.
Risk specification
SAPCAR contains an out-of-bounds memory read and write vulnerability that allows an authenticated attacker to write files to arbitrary directories, potentially altering file contents or system behavior.Solution
The memory corruption vulnerability has been addressed by implementing memory layout validation checks in SAPCAR.