CVE-2025-42935
BaseFortify
Publication date: 2025-08-12
Last updated on: 2025-08-12
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | netweaver_application_server_abap | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM). It allows authorized users who have admin privileges and local access to log files to read sensitive information. This results in information disclosure, impacting the confidentiality of the application.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive information by users with admin privileges who have local access to log files. This compromises the confidentiality of the application data but does not affect its integrity or availability.