PT-2025-1203 · Sap · Sap Netweaver Application Server Abap

Published

2025-01-13

·

Updated

2025-01-14

·

CVE-2025-0059

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP (affected versions not specified)
Description The issue concerns applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP, which store user input in the local browser storage to improve usability. This storage can be accessed by an attacker with administrative privileges or access to the victim's user directory on the Operating System level, potentially disclosing sensitive data. The impact of this disclosure can range from non-critical to highly sensitive information, affecting the confidentiality of the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-00577
CVE-2025-0059

Affected Products

Sap Netweaver Application Server Abap