← Back

CVE-2025-42878

nvd nist
Published: Dec 9, 2025Modified: Jun 17, 2026Deferred

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:H
Exploitability: 1.6 / Impact: 6.0
Source: CNA (Secondary)

Description

SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.

References (2)

Timeline

No history available yet.