Advisory
A note with CVSS 6.8 for component BC-MID-BUS was released by SAP on 11.11.2025. The correction/advisory 3665900 was described with "[CVE-2025-42892] OS Command Injection vulnerability in SAP Business Connector" and affects the system type SAP Business Connector.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is command injection within SAP Business Connector.
Risk specification
SAP Business Connector allows an authenticated attacker with administrative access to upload crafted content, resulting in the execution of arbitrary operating system commands on the server.Solution
The application now validates uploaded content to prevent unauthorized operating system command injection.
- 9.9 [CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)
- 7.2 [CVE-2020-6191] Missing Input Validation in SAP Landscape Management
- 7.2 [CVE-2020-6192] Missing Input Validation in SAP Landscape Management
- 7.2 [CVE-2020-6236] Privilege Escalation in SAP Landscape Management (SAP Adaptive Extensions)
- 7.2 [CVE-2020-6234] Privilege Escalation in SAP Host Agent
