DarkCrystal RAT aka DCRat – Active IOCs
June 12, 2025Multiple SolarWinds SWOSH Vulnerabilities
June 12, 2025DarkCrystal RAT aka DCRat – Active IOCs
June 12, 2025Multiple SolarWinds SWOSH Vulnerabilities
June 12, 2025Severity
Medium
Analysis Summary
CVE-2025-31325 CVSS:5.8
SAP NetWeaver (ABAP Keyword Documentation) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
CVE-2025-23192 CVSS:8.2
SAP BusinessObjects Business Intelligence (BI Workspace) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input.
CVE-2025-42994 CVSS:7.5
SAP MDM Server is vulnerable to a denial of service, caused by a memory read access violation flaw in the ReadString function in the server process.
CVE-2025-42995 CVSS:7.5
SAP MDM Server is vulnerable to a denial of service, caused by a memory read access violation in the server process.
CVE-2025-42996 CVSS:5.6
SAP MDM Server could allow a remote attacker to gain control of existing client sessions and execute certain functions, caused by improper access control.
CVE-2025-42998 CVSS:5.3
SAP Business One Integration Framework could allow a remote attacker to access restricted pages information, caused by improper validation jof security settings.
CVE-2025-42990 CVSS:3
SAP SAPUI5 applications is vulnerable to HTML injection. A remote authenticated attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site to show malicious content and/or redirect users to a malicious URL.
CVE-2025-42983 CVSS:8.5
SAP Business Warehouse and SAP Plug-In Basis could allow a remote authenticated attacker to drop arbitrary SAP database tables, caused by missing authorization validation.
Impact
- Cross-Site Scripting
- Security Bypass
- Information Disclosure
- Denial of Service
Indicators of Compromise
CVE
- CVE-2025-31325
- CVE-2025-23192
- CVE-2025-42995
- CVE-2025-42994
- CVE-2025-42996
- CVE-2025-42998
- CVE-2025-42990
- CVE-2025-42983
Affected Vendors
Affected Products
- SAP NetWeaver (ABAP Keyword Documentation) - SAP_BASIS 758
- SAP BusinessObjects Business Intelligence (BI Workspace) ENTERPRISE 430
- SAP BusinessObjects Business Intelligence (BI Workspace) 2025
- SAP BusinessObjects Business Intelligence (BI Workspace) 2027
- SAP MDM Server 710.750
- SAP Business One Integration Framework B1_ON_HANA 10.0
- SAP Business One Integration Framework SAP-M-BO 10.0
- SAP SAPUI5 applications SAP_UI 750
- SAP SAPUI5 applications SAP_UI 754
- SAP SAPUI5 applications SAP_UI 755
- SAP SAPUI5 applications SAP_UI 756
- SAP SAPUI5 applications SAP_UI 757
- SAP SAPUI5 applications SAP_UI 758
- SAP SAPUI5 applications UI_700 200
- SAP Business Warehouse and SAP Plug-In Basis PI_BASIS 2006_1_700
- SAP SAPBusiness Warehouse and SAP Plug-In Basis 701
- SAP Business Warehouse and SAP Plug-In Basis 702
- SAP Business Warehouse and SAP Plug-In Basis 731
- SAP Business Warehouse and SAP Plug-In Basis 740
- SAP Business Warehouse and SAP Plug-In Basis SAP_BW 750
- SAP Business Warehouse and SAP Plug-In Basis 751
- SAP Business Warehouse and SAP Plug-In Basis 752
- SAP Business Warehouse and SAP Plug-In Basis 753
- SAP Business Warehouse and SAP Plug-In Basis 754
- SAP Business Warehouse and SAP Plug-In Basis 755
- SAP Business Warehouse and SAP Plug-In Basis 756
- SAP Business Warehouse and SAP Plug-In Basis 757
- SAP Business Warehouse and SAP Plug-In Basis 758
Remediation
Refer to SAP Security Advisory for patch, upgrade, or suggested workaround information.(Login Required)