CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-42997: Information Disclosure vulnerability in SAP Gateway Client

6.6 CVSS

Description

Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality, integrity, and availability.

Classification

CVE ID: CVE-2025-42997

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.6

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Problem Types

CWE-732: Incorrect Permission Assignment for Critical Resource

Affected Products

Vendor: SAP_SE

Product: SAP Gateway Client

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 12.03% (scored less or equal to compared to others)

EPSS Date: 2025-06-11 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2025-42997
https://me.sap.com/notes/3577300
https://url.sap/sapsecuritypatchday

Timeline