Security Flaw in GuiXT Application Integrated with SAP GUI for Windows
CVE-2025-42979
5.6MEDIUM
What is CVE-2025-42979?
The GuiXT application, essential for customizing SAP GUI for Windows, suffers from a vulnerability due to its reliance on obfuscation algorithms rather than secure symmetric encryption methods for storing RFC user credentials. This oversight exposes user passwords stored in the Windows registry to potential attackers. If an attacker gains access to the user's registry hive, they can easily reconstruct the original passwords, resulting in compromised user confidentiality while leaving the application's integrity and availability unaffected. Implementing proper encryption mechanisms is crucial to fortifying defenses against unauthorized credential access.
Affected Version(s)
SAP GUI for Windows BC-FES-GUI 8.00