CVE-2025-42878

SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.
Configurations

No configuration.

History

09 Dec 2025, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 16:17

Updated : 2025-12-09 18:36


NVD link : CVE-2025-42878

Mitre link : CVE-2025-42878

CVE.ORG link : CVE-2025-42878


JSON object : View

Products Affected

No product.

CWE
CWE-1244

Internal Asset Exposed to Unsafe Debug Access Level or State