Security Flaw in GuiXT Application Integrated with SAP GUI for Windows
CVE-2025-42979

5.6MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
8 July 2025

What is CVE-2025-42979?

The GuiXT application, essential for customizing SAP GUI for Windows, suffers from a vulnerability due to its reliance on obfuscation algorithms rather than secure symmetric encryption methods for storing RFC user credentials. This oversight exposes user passwords stored in the Windows registry to potential attackers. If an attacker gains access to the user's registry hive, they can easily reconstruct the original passwords, resulting in compromised user confidentiality while leaving the application's integrity and availability unaffected. Implementing proper encryption mechanisms is crucial to fortifying defenses against unauthorized credential access.

Affected Version(s)

SAP GUI for Windows BC-FES-GUI 8.00

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42979 : Security Flaw in GuiXT Application Integrated with SAP GUI for Windows