CVE-2025-42878: Sensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on integrity and of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42878?
CVE-2025-42878 is considered to have a high severity due to its potential impact on confidentiality and service disruption.
How do I fix CVE-2025-42878?
To fix CVE-2025-42878, ensure that the internal testing interfaces in SAP Web Dispatcher and ICM are disabled in production environments.
What systems are affected by CVE-2025-42878?
CVE-2025-42878 affects SAP Web Dispatcher and SAP Internet Communication Manager (ICM) software.
What kind of attacks can be performed using CVE-2025-42878?
Using CVE-2025-42878, unauthenticated attackers could exploit the vulnerability to access diagnostics, send crafted requests, or disrupt services.
Is authentication required to exploit CVE-2025-42878?
No, CVE-2025-42878 can be exploited by unauthenticated attackers if the vulnerable interfaces are enabled.