CVE-2025-0058

MEDIUM

SAP - Info Disclosure

Title source: llm
STIX 2.1

Description

In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3542698

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (9)
sap/sap_basis 753
sap/sap_basis 754
sap/sap_basis 755
sap/sap_basis 756
sap/sap_basis 757
sap/sap_basis 758
sap/sap_basis 912
sap/sap_basis 913
sap/sap_basis 914
Published Jan 14, 2025
Tracked Since Feb 18, 2026