cbcvebase.
CVE-2025-0055
published 2025-01-14

CVE-2025-0055: SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or…

PriorityP426medium6CVSS 3.1
AVLACLPRHUINSCCHINAN
EPSS
0.23%
14.1th percentile
SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.

Affected

1 ranges
VendorProductVersion rangeFixed in
sap_sesap_gui_for_windows
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.