First published: Tue Mar 11 2025(Updated: )
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Web Dispatcher | ||
SAP NetWeaver Internet Communication Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0071 is classified as a high severity vulnerability due to its impact on the confidentiality of sensitive information.
To fix CVE-2025-0071, disable debugging trace mode and ensure administrative privileges are appropriately managed.
CVE-2025-0071 allows the exposure of unencrypted passwords in logs, which can lead to unauthorized access and data breaches.
CVE-2025-0071 affects users of SAP Web Dispatcher and SAP Internet Communication Manager with administrative privileges.
If you have CVE-2025-0071 in your environment, take immediate steps to mitigate the vulnerability by applying security best practices.