CVE-2025-42904
Due to an Information Disclosure vulnerability in Application Server ABAP, an authenticated attacker could read unmasked values displayed in ABAP Lists. Successful exploitation could lead to unauthorized disclosure of data, resulting in a high impact on confidentiality without affecting integrity or availability.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.33%
- CWE
- CWE-549
- Published
- 2025-12-09
- Last modified
- 2026-03-13
Affected products
- SAP_SE Application Server ABAP
- SAP_SE Application Server ABAP
- SAP_SE Application Server ABAP
- SAP_SE Application Server ABAP
- SAP_SE Application Server ABAP
- SAP_SE Application Server ABAP
- SAP_SE Application Server ABAP
- SAP_SE Application Server ABAP
Weakness type
Related vulnerabilities
- CVE-2026-3314 — Missing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpoint
- CVE-2025-13175 — Insecure Password Storage in Y Soft SafeQ 6
- CVE-2025-64170 — sudo-rs: Partial password reveal is possible after timeout
- CVE-2025-4526 — Dígitro NGC Explorer Configuration missing password field masking
- CVE-2025-0148 — Zoom Jenkins Marketplace plugin - Missing Password Field Masking
- CVE-2024-10122 — Topdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field masking
- CVE-2023-49106 — Missing Password Field Masking Vulnerability in Hitachi Device Manager
- CVE-2023-2062 — Information Disclosure vulnerability in EtherNet/IP Configuration tools