CVE-2025-42878 β Internal Asset Exposed to Unsafe Debug Access Level or State in SE SAP WEB Dispatcher AND Internet Communication Manager
Severity
8.2HIGHNVD
EPSS
0.2%
top 63.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9
Description
SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:HExploitability: 1.6 | Impact: 6.0