CVE-2025-42878

Published Dec 9, 2025

Last updated 9 days ago

Overview

Description
SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.
Source
cna@sap.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Primary
Base score
8.2
Impact score
6
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:H
Severity
HIGH

Weaknesses

cna@sap.com
CWE-1244

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.