Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.
History

Tue, 09 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap application Server Java
Vendors & Products Sap
Sap application Server Java

Tue, 09 Dec 2025 02:30:00 +0000

Type Values Removed Values Added
Description Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.
Title Information Disclosure vulnerability in Application Server ABAP
Weaknesses CWE-549
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-12-09T02:15:36.673Z

Updated: 2025-12-09T15:57:42.478Z

Reserved: 2025-04-16T13:25:25.736Z

Link: CVE-2025-42904

cve-icon Vulnrichment

Updated: 2025-12-09T15:57:39.875Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:17:52.993

Modified: 2025-12-09T18:36:53.557

Link: CVE-2025-42904

cve-icon Redhat

No data.