7.5
CVE-2025-42877
- EPSS 0.08%
- Veröffentlicht 09.12.2025 02:14:51
- Zuletzt bearbeitet 09.12.2025 18:36:53
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
≫
Produkt
SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Default Statusunaffected
Version
KRNL64UC 7.53
Status
affected
Version
WEBDISP 7.53
Status
affected
Version
7.54
Status
affected
Version
XS_ADVANCED_RUNTIME 1.00
Status
affected
Version
SAP_EXTENDED_APP_SERVICES 1
Status
affected
Version
CONTSERV 7.53
Status
affected
Version
KERNEL 7.53
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.233 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@sap.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.