SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or availability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00042}

epss

{'score': 0.00055}


Tue, 11 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or availability.
Title Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Manager
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-03-11T02:18:02.453Z

Reserved: 2024-12-11T05:05:13.719Z

Link: CVE-2025-0071

cve-icon Vulnrichment

Updated: 2025-03-11T02:17:51.453Z

cve-icon NVD

Status : Received

Published: 2025-03-11T01:15:33.917

Modified: 2025-03-11T01:15:33.917

Link: CVE-2025-0071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.