Description
Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.
Published: 2025-12-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap application Server Java
Vendors & Products Sap
Sap application Server Java

Tue, 09 Dec 2025 02:30:00 +0000

Type Values Removed Values Added
Description Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.
Title Information Disclosure vulnerability in Application Server ABAP
Weaknesses CWE-549
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Sap Application Server Java
cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-12-09T15:57:42.478Z

Reserved: 2025-04-16T13:25:25.736Z

Link: CVE-2025-42904

cve-icon Vulnrichment

Updated: 2025-12-09T15:57:39.875Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:17:52.993

Modified: 2025-12-09T18:36:53.557

Link: CVE-2025-42904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-09T10:04:29Z

Weaknesses