Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality, integrity, and availability.
History

Tue, 13 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 00:45:00 +0000

Type Values Removed Values Added
Description Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality, integrity, and availability.
Title Information Disclosure vulnerability in SAP Gateway Client
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-05-13T00:17:32.075Z

Updated: 2025-05-13T13:55:38.108Z

Reserved: 2025-04-16T13:25:50.942Z

Link: CVE-2025-42997

cve-icon Vulnrichment

Updated: 2025-05-13T13:55:34.702Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T01:15:48.293

Modified: 2025-05-13T19:35:25.503

Link: CVE-2025-42997

cve-icon Redhat

No data.