We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-42935

Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Manager)



Description

The SAP NetWeaver Application Server ABAP and ABAP Platform Internet Communication Manager (ICM) permits authorized users with admin privileges and local access to log files to read sensitive information, resulting in information disclosure. This leads to high impact on the confidentiality of the application, with no impact on integrity or availability.

Reserved 2025-04-16 | Published 2025-08-12 | Updated 2025-08-12 | Assigner sap


MEDIUM: 4.1CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-532: Insertion of Sensitive Information into Log File

Product status

Default status
unaffected

KRNL64NUC 7.22
affected

7.22EXT
affected

KRNL64UC 7.22
affected

7.53
affected

KERNEL 7.22
affected

7.54
affected

7.77
affected

7.89
affected

7.93
affected

9.14
affected

9.15
affected

9.16
affected

References

me.sap.com/notes/3601480

url.sap/sapsecuritypatchday

cve.org (CVE-2025-42935)

nvd.nist.gov (CVE-2025-42935)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-42935

Support options

Helpdesk Chat, Email, Knowledgebase