CVE-2025-0059
CVSS 3.1 Score 6.0 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 497
Summary
CVE-2025-0059 is a vulnerability affecting applications using SAP GUI for HTML in SAP NetWeaver Application Server ABAP. This issue arises due to the storage of user input in the local browser, which can be accessed by attackers with administrative privileges or OS-level access to the victim's user directory. The data exposed through this vulnerability can vary from non-critical to highly sensitive, leading to significant confidentiality concerns.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sap Netweaver Application Server Abap
Affected Vendors
- SAP SE