Local Information Disclosure in SAP GUI for Windows by SAP
CVE-2025-42888

5.5MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
11 November 2025

What is CVE-2025-42888?

The SAP GUI for Windows could allow a highly privileged user to access sensitive information stored in process memory during runtime. This vulnerability presents risks to confidentiality by enabling unauthorized local access to potentially sensitive data, while having no impact on the integrity or availability of the application. It is imperative for users to remain vigilant and apply security patches to mitigate this risk.

Affected Version(s)

SAP GUI for Windows BC-FES-GUI 8.00

SAP GUI for Windows 8.10

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42888 : Local Information Disclosure in SAP GUI for Windows by SAP