CVE-2025-0058: Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow
In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0058?
CVE-2025-0058 has a high severity rating due to the potential exposure of sensitive information.
How can I mitigate CVE-2025-0058?
Mitigation for CVE-2025-0058 involves applying the latest patches provided by SAP for the affected workflows.
Who is affected by CVE-2025-0058?
CVE-2025-0058 affects users of SAP Business Workflow and SAP Flexible Workflow where authenticated attacks can occur.
What type of vulnerability is CVE-2025-0058?
CVE-2025-0058 is categorized as an information disclosure vulnerability.
Is CVE-2025-0058 exploitable remotely?
CVE-2025-0058 requires authenticated access, hence it is not exploitable remotely by unauthorized users.