Debugging Vulnerability in SAP Web Dispatcher and Internet Communication Manager
CVE-2025-0071

4.9MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
11 March 2025

Summary

SAP Web Dispatcher and Internet Communication Manager present a significant risk as they allow an attacker with administrative privileges to enable debugging trace mode through a specific parameter. This misconfiguration can lead to the exposure of unencrypted passwords in application logs, thereby compromising the confidentiality of sensitive information. This vulnerability does not affect the integrity or availability of the application.

Affected Version(s)

SAP Web Dispatcher and Internet Communication Manager KRNL64UC 7.53

SAP Web Dispatcher and Internet Communication Manager WEBDISP 7.53

SAP Web Dispatcher and Internet Communication Manager 7.54

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.