CVE-2025-0055
CVSS 3.1 Score 6 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 497
Summary
CVE-2025-0055 is a vulnerability affecting SAP GUI for Windows. The issue arises due to the application's practice of storing user input data on the client PC for usability enhancements. If an attacker gains administrative privileges or access to the victim's user directory at the OS level, they can exploit this vulnerability to read the sensitive data. The extent of the data disclosure can vary from non-critical information to highly confidential data, leading to significant risks for the application's confidentiality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sap Gui For Windows
Affected Vendors
- SAP SE