Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3595156
was released on
08.07.2025 and deals with
"[CVE-2025-42970] Directory Traversal vulnerability in SAPCAR" within SAPCAR.
We advice you to follow the instructions, to resolve
directory traversal (write)
with a
medium potential for exploitation
in component BC-INS-TLS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
SAPCAR allows an authenticated attacker to write files to arbitrary directories, potentially leading to unauthorized modification of file contents or alteration of system behavior.Solution
With this fix, SAPCAR now performs strict validation of file paths during archive extraction to prevent unauthorized file writes.