CVE-2025-0055

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 497

Summary

CVE-2025-0055 is a vulnerability affecting SAP GUI for Windows. The issue arises due to the application's practice of storing user input data on the client PC for usability enhancements. If an attacker gains administrative privileges or access to the victim's user directory at the OS level, they can exploit this vulnerability to read the sensitive data. The extent of the data disclosure can vary from non-critical information to highly confidential data, leading to significant risks for the application's confidentiality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sap Gui For Windows

Affected Vendors

  • SAP SE