CVE-2025-42910 is a critical unrestricted file upload vulnerability in SAP Supplier Relationship Management (SRM). The flaw is caused by missing server-side verification of uploaded file type or content in SRM file upload functionality, allowing an authenticated attacker to submit arbitrary files instead of only expected safe document types. The uploaded content can include executable or otherwise dangerous files that may later be downloaded and run by users, or processed in an unsafe manner by application components. The vulnerability affects supported SAP SRM releases prior to the vendor patch issued in September 2025; public reporting did not disclose exact affected version numbers.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unrestricted file upload vulnerability in SAP Supplier Relationship Management that allows attackers to upload arbitrary files, including malicious executables.
A critical unrestricted file upload vulnerability in SAP Supplier Relationship Management that allows authenticated attackers to upload arbitrary files, potentially leading to malware execution and high impact on confidentiality, integrity, and availability.
A critical unrestricted file upload vulnerability in SAP Supplier Relationship Management (SRM) caused by insufficient server-side validation of uploaded file type and content.
An unrestricted file upload vulnerability in SAP Supplier Relationship Management (SRM) that could allow authenticated attackers to upload arbitrary files, potentially including malware executables.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.