CVE-2025-24870
SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.17%
- CWE
- CWE-921
- Published
- 2025-02-11
- Last modified
- 2026-03-12
Affected products
- SAP_SE SAP GUI for Windows
Weakness type
Related vulnerabilities
- CVE-2025-30016 — Authentication Bypass Vulnerability in SAP Financial Consolidation
- CVE-2025-24843 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Storage of Sensitive Data in a Mechanism without Access Control
- CVE-2024-9334 — Information Disclosure in E-Kent's Pallium Vehicle Tracking
- CVE-2024-5206 — Sensitive Data Leakage in sklearn.feature_extraction.text.TfidfVectorizer in scikit-learn/scikit-learn
- CVE-2023-41818
- CVE-2023-41965 — Socomec MOD3GP-SY-120K Insecure Storage of Sensitive Information
- CVE-2023-2665 — Storage of Sensitive Data in a Mechanism without Access Control in francoisjacquet/rosariosis
- CVE-2021-27456 — Philips Gemini PET/CT Storage of Sensitive Data in a Mechanism Without Access Control