CVE-2025-0059

CVSS 3.1 Score 6.0 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 497

Summary

CVE-2025-0059 is a vulnerability affecting applications using SAP GUI for HTML in SAP NetWeaver Application Server ABAP. This issue arises due to the storage of user input in the local browser, which can be accessed by attackers with administrative privileges or OS-level access to the victim's user directory. The data exposed through this vulnerability can vary from non-critical to highly sensitive, leading to significant confidentiality concerns.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Sap Netweaver Application Server Abap

Affected Vendors

  • SAP SE