4.1

CVE-2025-42935

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the application, with no impact on integrity or availability.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSAP_SE
Produkt SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Manager)
Default Statusunaffected
Version KRNL64NUC 7.22
Status affected
Version 7.22EXT
Status affected
Version KRNL64UC 7.22
Status affected
Version 7.53
Status affected
Version KERNEL 7.22
Status affected
Version 7.54
Status affected
Version 7.77
Status affected
Version 7.89
Status affected
Version 7.93
Status affected
Version 9.14
Status affected
Version 9.15
Status affected
Version 9.16
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@sap.com 4.1 0.5 3.6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.