CVE-2025-42878 β€” Internal Asset Exposed to Unsafe Debug Access Level or State in SE SAP WEB Dispatcher AND Internet Communication Manager

Severity
8.2HIGHNVD
EPSS
0.2%
top 63.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9

Description

SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages1 packages

πŸ”΄Vulnerability Details

2
GHSA
GHSA-549v-r8j8-4rmh: SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production↗2025-12-09
β–Ά
CVEList
Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)β†—2025-12-09
β–Ά
CVE-2025-42878 β€” HIGH severity | cvebase