CVE-2025-0071: Information Disclosure vulnerability in SAP Web Dispatcher and Internet Communication Manager
SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0071?
CVE-2025-0071 is classified as a high severity vulnerability due to its impact on the confidentiality of sensitive information.
How do I fix CVE-2025-0071?
To fix CVE-2025-0071, disable debugging trace mode and ensure administrative privileges are appropriately managed.
What effect does CVE-2025-0071 have on my system?
CVE-2025-0071 allows the exposure of unencrypted passwords in logs, which can lead to unauthorized access and data breaches.
Who is affected by CVE-2025-0071?
CVE-2025-0071 affects users of SAP Web Dispatcher and SAP Internet Communication Manager with administrative privileges.
What should I do if I have CVE-2025-0071 in my environment?
If you have CVE-2025-0071 in your environment, take immediate steps to mitigate the vulnerability by applying security best practices.