Advisory
A note with CVSS 6.8 for component BC-MID-BUS was released by SAP on 11.11.2025. The correction/advisory 3666038 was described with "[CVE-2025-42894] Path Traversal vulnerability in SAP Business Connector" and affects the system type SAP Business Connector.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is directory traversal within SAP Business Connector.
Risk specification
SAP Business Connector allows an authenticated attacker with administrative access to read, write, overwrite, and delete arbitrary files on the host system, resulting in unauthorized execution of operating system commands.Solution
The application now implements validation checks to block unauthorized file system access and prevent path traversal attacks.
- 9.8 [CVE-2025-42937] Directory Traversal vulnerability in SAP Print Service
- 9.6 [CVE-2023-27500] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
- 9.6 [CVE-2023-27269] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
- 8.7 [CVE-2022-41214] Multiple vulnerabilities in SAP NetWeaver Application Server ABAP and ABAP Platform
- 8.7 [CVE-2023-27501] Directory Traversal vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
