Home

Description

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality, integrity, and availability.

PUBLISHED Reserved 2025-04-16 | Published 2025-05-13 | Updated 2025-05-13 | Assigner sap




MEDIUM: 6.6CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Problem types

CWE-732: Incorrect Permission Assignment for Critical Resource

Product status

Default status
unaffected

SAP_GWFND 752
affected

753
affected

754
affected

755
affected

756
affected

757
affected

758
affected

References

me.sap.com/notes/3577300

url.sap/sapsecuritypatchday

cve.org (CVE-2025-42997)

nvd.nist.gov (CVE-2025-42997)

Download JSON