SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.
References
Configurations
No configuration.
History
09 Dec 2025, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-09 16:17
Updated : 2025-12-09 18:36
NVD link : CVE-2025-42878
Mitre link : CVE-2025-42878
CVE.ORG link : CVE-2025-42878
JSON object : View
Products Affected
No product.
CWE
CWE-1244
Internal Asset Exposed to Unsafe Debug Access Level or State
