Debugging Vulnerability in SAP Web Dispatcher and Internet Communication Manager
CVE-2025-0071
4.9MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 11 March 2025
Summary
SAP Web Dispatcher and Internet Communication Manager present a significant risk as they allow an attacker with administrative privileges to enable debugging trace mode through a specific parameter. This misconfiguration can lead to the exposure of unencrypted passwords in application logs, thereby compromising the confidentiality of sensitive information. This vulnerability does not affect the integrity or availability of the application.
Affected Version(s)
SAP Web Dispatcher and Internet Communication Manager KRNL64UC 7.53
SAP Web Dispatcher and Internet Communication Manager WEBDISP 7.53
SAP Web Dispatcher and Internet Communication Manager 7.54
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved