SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap web Dispatcher And Internet Communication Manager |
|
| Vendors & Products |
Sap
Sap web Dispatcher And Internet Communication Manager |
Tue, 09 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application. | |
| Title | Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM) | |
| Weaknesses | CWE-1244 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-12-09T02:14:59.636Z
Updated: 2025-12-09T16:39:27.411Z
Reserved: 2025-04-16T13:25:17.023Z
Link: CVE-2025-42878
Updated: 2025-12-09T16:39:24.018Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:52.230
Modified: 2025-12-09T18:36:53.557
Link: CVE-2025-42878
No data.