CVE-2025-42903
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-10-14
Assigner: SAP SE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sap | financial_service_claims_management | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-204 | The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SAP Financial Service Claims Management RFC function ICL_USER_GET_NAME_AND_ADDRESS. It allows an attacker to perform user enumeration and potentially disclose personal data by observing differences in responses. The impact on confidentiality is low, and there is no impact on integrity or availability.
How can this vulnerability impact me? :
The vulnerability can lead to user enumeration and limited disclosure of personal data, which may expose some confidential information. However, it does not affect the integrity or availability of the system, so the overall impact is limited to confidentiality with a low severity.